vendor:
VWar
by:
SecurityFocus
7.5
CVSS
HIGH
Multiple HTML-injection, SQL-injection, Unauthorized-access, Brute-force authentication credentials
79, 89, 522, 539, 287
CWE
Product Name: VWar
Affected Version From: VWar 1.6.1 R2
Affected Version To: VWar 1.6.1 R2
Patch Exists: YES
Related CWE: N/A
CPE: a:vwar:vwar:1.6.1_r2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
VWar Multiple Remote Vulnerabilities
An attacker can exploit these issues to compromise the affected application, gain unauthorized access to the application, execute arbitrary script code, steal cookie-based authentication credentials, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are also possible.
Mitigation:
Ensure that all input is validated and filtered before being used in the application. Ensure that all output is properly encoded before being sent to the user. Use a web application firewall to detect and block malicious input.