vendor:
PHPKIT
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting, SQL Injection
79, 89
CWE
Product Name: PHPKIT
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
PHPKIT Cross-Site Scripting and SQL Injection Vulnerabilities
The cross-site scripting issue is present in a parameter of the 'popup.php' script. An attacker can exploit this issue by creating a malicious link containing HTML and script code and send this link to a vulnerable user. This can allow for theft of cookie-based authentication credentials and other attacks. An SQL injection issue exists in the application as well. This issue affects a parameter of the 'print.php' script. Due to this, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries.
Mitigation:
Apply the latest patches or updates from the vendor. Validate and sanitize user input to prevent cross-site scripting and SQL injection attacks. Use prepared statements or parameterized queries to prevent SQL injection.