static XSS / SQL-Injection in Omegasoft Insel

2007.06.05
Credit: MC Iglo
Risk: Medium
Local: Yes
Remote: Yes
CWE: CWE-79

Input passed to fields in OmegaMw7's tables isn't properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site and/or inject SQL-Commands This applies to many many standard fields in different tables e.g. F05003, F05005, F05015 and to all user-created text fields using the form creator (you cannot do it a different way) kind regards MC.Iglo


Vote for this issue:
50%
50%

Comment it here.

Copyright 2025, cxsecurity.com

 

Back to Top