Pixelpost Cross Site Scripting and SQL Injection Vulnerabilities
BID:43300
Info
Pixelpost Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 43300 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2009 12:00AM |
| Updated: | Sep 02 2009 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
pixelpost Pixelpost 1.7.1 pixelpost Pixelpost 1.7.2 pixelpost Pixelpost 1.7 |
| Not Vulnerable: |
pixelpost Pixelpost 1.7.3 |
Exploit / POC
Pixelpost Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Pixelpost Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Pixelpost Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- CVE request: pixelpost (Pixelpost)
- Pastie: 616485 (Jay Williams)
- Pixelpost 1.7.3 (security update) September 2, 2009 (Pixelpost)
- Pixelpost Homepage (Pixelpost)