2 results (0.007 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 4

Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Open Media Collectors Database (OpenDb) 1.0.6 permiten a atacantes remotos inyectar arbitrariamente secuencias de comandos web o HTML a través de los parámetros (1) user_id parameter en una acción edit en user_admin.php, (2) title en listings.php y (3) redirect_url en user_profile.php. • https://www.exploit-db.com/exploits/32314 https://www.exploit-db.com/exploits/32313 https://www.exploit-db.com/exploits/32315 http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txt http://secunia.com/advisories/31719 http://www.securityfocus.com/bid/30989 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.8EPSS: 0%CPEs: 1EXPL: 1

Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action. Vulnerabilidad de falsificación de petición en sitios cruzados (CSFR) de user_admin.php en Open Media Collectors Database (OpenDb) 1.0.6 permite a atacantes remotos cambiar arbitrariamente contraseñas mediante una acción update_password. • http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txt http://secunia.com/advisories/31719 • CWE-352: Cross-Site Request Forgery (CSRF) •