Proman Xpress v5.0.1 – Multiple Web Vulnerabilities
The Vulnerability Laboratory Researcher Team discovered multiple Web Vulnerabilities in Proman Xpress 2012 Q2. A remote SQL Injection vulnerability is detected in the Promans Xpress 2012 Q2 content management system. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise. The vulnerability is located on the username post method. A persistent input validation vulnerability is detected n the Promans Xpress 2012 Q2 content management system. The bugs allow remot attackers to inject malicious script codes on application side (persistent). The vulnerability is located on the username post method.