vendor:
N/A
by:
Milw0rm.com, J.F.Cebrian
8,8
CVSS
HIGH
Sql injection, Stored Xss and CSRF
89, 79, 352
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Sql injection, Stored Xss and CSRF
The first three URLs are vulnerable to SQL injection. The fourth URL is vulnerable to stored XSS attack. The fifth and sixth URLs are vulnerable to CSRF attack.
Mitigation:
Input validation, use of prepared statements, use of stored procedures, use of parameterized queries, use of least privilege, use of secure coding practices, use of secure authentication and authorization, use of secure session management, use of secure communication protocols, use of secure data storage, use of secure data transmission, use of secure data destruction, use of secure data access control, use of secure data encryption, use of secure data integrity, use of secure data backup and recovery, use of secure data logging and auditing.