E-Local Business Directory SQL Injection

2013.09.10
Credit: Lazmania61
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

< ------------------- header data start ------------------- > ############################################################# # Application Name : E-Local Business Directory # Vulnerable Type : Post Sql Injection # Infection : Ynetici ve User cookieleri alnabilir. # Bug Fix Advice : Zararl karakterler filtrelenmelidir. # Author : Lazmania61 # Script Home Page: http://www.peoplesinnovation.com/local-business-directory-php-script.html # Example : http://nilusindia.easy2outsource.com/ ############################################################# < ------------------- header data end of ------------------- > < -- bug code start -- > Post Parameter Name = category_val Post Parameter Value = 88a < -- bug code end of -- >

References:

http://www.peoplesinnovation.com/local-business-directory-php-script.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top