Description
|
|
Multiple vulnerabilities have been identified in OpenBiblio, which could be exploited by remote attackers to execute SQL commands or include local files.
The first flaw is due to an unspecified input validation error when processing certain variables, which could be exploited by malicious users with "report" privileges to conduct SQL injection attacks.
The second issue is due to input validation errors in the "shared/header.php" and "shared/help.php" scripts that do not validate certain parameters, which could be exploited by attackers to include local files with the privileges of the web server.
|