|
|||
Rule General Information |
---|
Release Date: | 2019-06-13 | |
Rule Name: | My Little Forum 'index.php' SQL Injection Vulnerability -3 (CVE-2015-1435) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php. | |
Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:72582 http://mylittleforum.net/forum/index.php?id=8182 http://packetstormsecurity.com/files/130356/My-Little-Forum-2.3.3-Cross-Site-Scripting-SQL-Injection.html http://www.securityfocus.com/archive/1/534681/100/0/threaded |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: http://mylittleforum.net/forum/index.php?id=8182 |