Description
|
|
Multiple vulnerabilities have been identified in Dating Agent PRO, which could be exploited by remote attackers to disclose sensitive information or execute arbitrary scripting code.
The first flaw is due to input validation errors in the "index.php" and "search.php" scripts that do not validate the "login" parameter, which could be exploited by malicious people to conduct cross site scripting attacks.
The second issue is due to an error where the "requirements.php" script is accessible without requiring authentication, which could be exploited by attackers to obtain system information returned by the "phpinfo()" function.
|