vendor:
Video Community portal
by:
L0rd CrusAd3r aka VSN
5.5
CVSS
MEDIUM
SQLi and XSS
89
CWE
Product Name: Video Community portal
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:2daybiz:video_community_portal:1
Platforms Tested:
2010
Video Community portal SQLi and XSS Vulnerable
2daybiz Video Community portal is the ultimate solution for starting your video sharing and uploading community similar to YouTube, Daily Motion and Myspace Videos. This enterprise level video sharing software offers a powerful and rich featured solution. In this software members can upload videos, rate videos, tag videos, leave comments, edit uploaded videos, title and description set video as public/private, video play list, create channels, groups and favorite videos.
Mitigation:
Implement proper input validation and sanitization techniques to prevent SQLi and XSS attacks. Regularly update the software to fix any vulnerabilities.