Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6375 (Bitweaver)

BugsAlert Home > CVE-2007-6375 (Bitweaver)
 
 

Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also reported injection via JavaScript code in the Search box, but this is probably a forced SQL error or other separate primary issue.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6375

Learn more about CVE-2007-6375 (Bitweaver)
 
Tags: cve-2007-6375 bitweaver

Related Items

      CVE-2008-2748 (Skulltag)

      Vuln: NSSBoard Multiple HTML Injection Vulnerabilities

      Foxit Reader PDF XObject Processing Memory Corruption

      TROJ_VUNDO.ALU

      CVE-2008-5606 (qmail_mailing_list_manager)

      CVE-2008-5270 (yuhhu_superstar_2008)

      ?Hacktivism? Incidents Escalate, Become More Frequent

 

Pixel