SQL Injection and XSS Vulnerabilities in indexcity

Summary for SQL Injection and XSS Vulnerabilities in indexcity

Vulnerability
SQL Injection and XSS Vulnerabilities in indexcity
Discovered
2006.08.21
Last Update
2006.08.31 Exploitation code published
ID
EV0135
CVE
CVE-2006-4323 CVE-2006-4324
Risk Level
medium
Type
Multiple Vulnerabilities
Status
Unpatched. No reply from developer(s)
Vendor
CityForFree
Vulnerable Software
indexcity
Version
1.0
PoC/Exploit
Available
Solution
Not available
Discovered by
Aliaksandr Hartsuyeu (eVuln.com)

Order Source Code Audit

Check a site by source code review of your website or web application done by Aliaksandr Hartsuyeu.The order will be done by specialists in web security.