MiniTwitter SQL Injection and Cross Site Scripting Vulnerabilities
Description
Multiple vulnerabilities have been identified in MiniTwitter, which could be exploited by attackers to manipulate or disclose certain data.
The first issues are caused by input validation errors when displaying email addresses, which could allow cross site scripting attacks.
The second vulnerability is caused by input validation errors in the "inc/opt.php" script when processing user-supplied parameters (e.g. "apellidos"), which could be exploited by malicious people to conduct SQL injection attacks and maniulate other users' options.
Vulnerable Products
Vulnerable Software: MiniTwitter version 0.3 Beta and prior