vendor:
427BB
by:
CWH Underground
8.8
CVSS
HIGH
SQL Injection and XSS
89 (SQL Injection) and 79 (XSS)
CWE
Product Name: 427BB
Affected Version From: 2.3.2001
Affected Version To: 2.3.2001
Patch Exists: NO
Related CWE: N/A
CPE: 427bb:427bb:2.3.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
427BB 2.3.1 (SQL/XSS) Multiple Remote Vulnerabilities
A SQL injection vulnerability exists in showpost.php due to improper sanitization of user-supplied input. An attacker can exploit this vulnerability to execute arbitrary SQL commands in the application's database. Multiple XSS vulnerabilities exist in register.php, reminder.php, and search.php due to improper sanitization of user-supplied input. An attacker can exploit these vulnerabilities to inject arbitrary HTML and script code into the application's web pages.
Mitigation:
Input validation should be used to prevent SQL injection and XSS attacks. All user-supplied input should be validated and filtered before being used in SQL queries or HTML output.