Multi Website "Browse" Parameter SQL Injection Issue

Tuesday, October 5, 2010


Multi Website is a PHP-based web application. The application is exposed to an SQL injection issue because it fails to properly sanitize user-supplied input before using it in an SQL query. Specifically, this issue affects the "Browse" parameter when the "action" parameter is set to "vote". Multi Website version 1.5 is affected.

Ref: http://www.securityfocus.com/bid/43243

10.40.31 - CVE: CVE-2009-3150
Platform: Web Application - SQL Injection

0 comments:

Most Recent Post

MORE ON ARCHIVE
Widget by Mad Tomato

Help Me Expose This Article in Bulk!

Bookmark & Share

- OR -

SELECT YOUR PREFERRED ONE:

Bookmark and Share