vendor:
Magic Book Professional, Magic List Professional, Magic Forum Personal
by:
Not specified
5.5
CVSS
MEDIUM
Input Validation
89
CWE
Product Name: Magic Book Professional, Magic List Professional, Magic Forum Personal
Affected Version From: Magic Book Professional version 2.0 and prior, Magic List Professional version 2.5 and prior, and Magic Forum Personal versions 2.5 and prior
Affected Version To: Not specified
Patch Exists: NO
Related CWE: CVE-2005-4204
CPE: a:cfmagic:magic_book_professional:2.0cpe:/a:cfmagic:magic_list_professional:2.5cpe:/a:cfmagic:magic_forum_personal:2.5
Platforms Tested: Not specified
2005
CFMagic Products Multiple Input Validation Vulnerabilities
The CFMagic Products are prone to multiple input validation vulnerabilities. These vulnerabilities allow an attacker to inject malicious SQL code into database queries and conduct cross-site scripting attacks. An attacker can exploit these vulnerabilities by sending specially crafted input to the affected application.
Mitigation:
The vendor has not provided a specific mitigation or remediation for these vulnerabilities. It is recommended to update to the latest version of the CFMagic Products to address these issues.