XSS and Multiple SQL Injection in CzarNews

Summary for XSS and Multiple SQL Injection in CzarNews

Vulnerability
XSS and Multiple SQL Injection in CzarNews
Discovered
2006.04.04
Last Update
2006.04.14 Exploitation code published
ID
EV0118
CVE
CVE-2006-1640 CVE-2006-1641
Risk Level
medium
Type
Multiple Vulnerabilities
Status
Unpatched. Vendor notyfied.
Vendor
n/a
Vulnerable Software
CzarNews
Version
1.14
PoC/Exploit
Available
Solution
Not available
Discovered by
Aliaksandr Hartsuyeu (eVuln.com)

Order Source Code Analysis

Check a website by source code testing of a website or web application made by Aliaksandr Hartsuyeu.The work will be done by specialists in web application security.