Secunia Advisory SA32705
FloSites Blog "cat" and "category" SQL Injection Vulnerabilities
|
|
|
DescriptionVrs-hCk has reported some vulnerabilities in FloSites Blog, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "cat" and "category" parameters in index.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Solution Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by Vrs-hCk
Original Advisory http://milw0rm.com/exploits/7133
Deep Links
Links available in Customer Area
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new
versions, exploits, faulty patches, links, and other relevant data by
posting comments to this Advisory. You can also send this information to
vuln@secunia.com
No posts yet
|
|

You must be logged in to post a comment.
|
|
|