Football Website Manager SQL Injection and Multiple HTML Injection Vulnerabilities
BID:47593
Info
Football Website Manager SQL Injection and Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 47593 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2011 12:00AM |
| Updated: | Apr 26 2011 12:00AM |
| Credit: | **RoAd_KiLlEr** |
| Vulnerable: |
Cycsoft Football Website Manager 1.1 |
| Not Vulnerable: | |
Exploit / POC
Football Website Manager SQL Injection and Multiple HTML Injection Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/profile.php?fileId=[SQL Injection]
An attacker can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/profile.php?fileId=[SQL Injection]
References
Football Website Manager SQL Injection and Multiple HTML Injection Vulnerabilities
References:
References:
- Football Website Manager (Cycsoft)