exploit-db-mirror/exploits/php/webapps/25216.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

7 lines
No EOL
509 B
Text

source: http://www.securityfocus.com/bid/12788/info
Multiple SQL injection and cross-site scripting vulnerabilities exist in paFileDB. These issues are reported to exist in the 'viewall.php' and 'category.php' scripts.
Exploitation of these issues may allow for compromise of the software, session hijacking, or attacks against the underlying database.
http://www.example.com/[pafiledb_dir]/pafiledb.php?action=category&start="><iframe%20src=http://www.securityreason.com></iframe>&sortby=date