vendor:
Zoph Organizes Photos
by:
Manuel Garcia Cardenas
N/A
CVSS
N/A
SQL Injection and Cross-Site Scripting
89, 79
CWE
Product Name: Zoph Organizes Photos
Affected Version From: Zoph <= 0.9.1
Affected Version To: Zoph <= 0.9.1
Patch Exists: NO
Related CWE: N/A
CPE: a:zoph:zoph
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web based
2014
Multiple Vulnerabilities in Zoph <= 0.9.1
It is possible to inject SQL code in the variables 'id' and 'action' on the pages group, photos and user. This bug was found using the portal with authentication. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application. Has been detected a reflected XSS vulnerability in Zoph, that allows the execution of arbitrary HTML/script code to be executed in the context of the victim user's browser.
Mitigation:
No news releases