vendor:
Freelancers Script V.1
by:
IRCRASH (Dr.Crash)
7.5
CVSS
HIGH
Multiple Remote Vulnerabilities (SQL Injection Exploit/XSS)
CWE
Product Name: Freelancers Script V.1
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Softbiz Freelancers Script V.1
Softbiz Freelancers Script V.1 is affected by multiple vulnerabilities including SQL Injection and XSS. The SQL Injection vulnerability can be exploited by manipulating the 'search_form.php' parameter 'sb_showresult' to execute arbitrary SQL queries. The XSS vulnerability can be exploited by injecting malicious scripts into the 'errmsg' parameter of the 'signin.php' page.
Mitigation:
The vendor has not provided any specific mitigation or remediation steps for these vulnerabilities.