Thứ Sáu, 30 tháng 11, 2012

Sphpforum 0.4 Cross Site Scripting / SQL Injection

# Product: sphpforum
# Version: 0.4 (older versions may be affected)
#
# Software Download: http://sourceforge.net/projects/sphpforum/

# Description:
# Simple PHP Forum is a PHP based forum/BBS board is designed to be small, simple,
# fast and allow easy integration into any existing web site.

# Vulnerability:
# Due to improper input sanitation, parameters are prone to SQL injection. Stored
# crossed site scripting is also present in some forms.
READ MORE »

Không có nhận xét nào:

Đăng nhận xét