Description
|
|
Multiple vulnerabilities have been identified in BXR, which could be exploited by attackers to disclose sensitive information or inject SQL queries. These issues are caused by input validation errors in the "settings/update_settings", "search/show_results", and "folder/list" scripts when processing the "setting[site_title]", "search[query]" or "order_by" paremeters, or user-supplied URLs, which could be exploited to conduct SQL injection or cross site scripting attacks.
|