Lucene search

K
exploitdbL4teralEDB-ID:30996
HistoryJan 07, 2008 - 12:00 a.m.

eTicket 1.5.5.2 - 'search.php' Multiple SQL Injections

2008-01-0700:00:00
L4teral
www.exploit-db.com
17

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/27173/info
  
eTicket is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These vulnerabilities include multiple SQL-injection issues, a cross-site scripting issue, and an authentication-bypass issue.
  
A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user.
  
These issues affect eTicket 1.5.5.2; other versions may also be affected.

http://www.example.com/eTicket/search.php?s=advanced&text=test&cat=&status=open'SQL&search_submit=Search

AI Score

7.4

Confidence

Low

Related for EDB-ID:30996