vendor:
Machform form maker
by:
Yashar shahinzadeh
7.5
CVSS
HIGH
Arbitrary file upload, MySQL Injection (Error based) and XSS
434, 89
CWE
Product Name: Machform form maker
Affected Version From: 2
Affected Version To:
Patch Exists: No
Related CWE:
CPE:
Platforms Tested: Linux & Windows, PHP 5.2.9
2013
Machform form maker – Multiple Vulnerabilities
The Machform form maker has multiple vulnerabilities, including arbitrary file upload, MySQL injection (error based), and XSS. The arbitrary file upload vulnerability allows an attacker to upload files to the server. The MySQL injection vulnerability allows an attacker to execute malicious SQL queries. The XSS vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users. These vulnerabilities can be exploited by an attacker to gain unauthorized access to the system, steal sensitive information, or perform other malicious activities.
Mitigation:
To mitigate these vulnerabilities, it is recommended to update to the latest version of Machform form maker and apply any available patches or security updates. Additionally, it is important to sanitize user input and implement proper input validation and output encoding to prevent SQL injection and XSS attacks.