Ansel Multiple Input Validation...

- AV AC AU C I A
发布: 2004-12-06
修订: 2025-04-13

It is reported that Ansel is susceptible to cross-site scripting and SQL injection vulnerabilities. The cross-site scripting issue is present in the 'album name' parameter of the Ansel application. An attacker can exploit this issue by creating a malicious link containing HTML and script code and send this link to a vulnerable user. An SQL injection issue exists in the application as well. This issue affects the 'image' parameter of the Ansel application. Due to this, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息