Description
|
|
Multiple vulnerabilities have been identified in Xt-News, which could be exploited by remote attackers to execute arbitrary SQL commands or scripting code.
The first flaw is due to an input validation error in the "show_news.php" script when processing the "id_news" parameter, which could be exploited by malicious people to conduct SQL injection attacks.
The second flaw is due to input validation errors in the "add_comment.php" and "show_news.php" scripts when processing the "id_news" parameter, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|