vendor:
N/A
by:
SecurityFocus
7.5
CVSS
HIGH
SQL Injection, Cross-Site Scripting, HTML Injection, and Information Disclosure
89, 79, 200, 564
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Multiple Vulnerabilities in Software
Multiple vulnerabilities have been reported to exist in the software that may allow an attacker to carry out attacks against the database, disclose sensitive information, and execute HTML or script code in a user's browser. The issues include SQL injection, cross-site scripting, HTML injection, and information disclosure.
Mitigation:
Input validation, sanitization, and output encoding should be used to prevent these vulnerabilities.