News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
SecWatch.org:
CJ Tag Board Multiple Parameter Handling PHP Code Injection Vulnerabilities
August 30, 2006 @ 08:18:29

According to this posting on the SecWatch board today, there are some issues with the CJ Tag Board software that allow for code injection issues.

Multiple input validation vulnerabilities in CJ Tag Board have been reported, which can be exploited by remote users to compromise a vulnerable system.

The issue comes from improperly filtered user input for the "User-Agent" HTTP header and the "banned" parameter for the admin side. This issue effects CJ Tag Board version 3.0. No update or patch has been posted as of yet to correct this issue.

0 comments voice your opinion now!
vulnerabilities code injection parameter handing filter input vulnerabilities code injection parameter handing filter input



Similar Posts

The Codist Blog: I Will Never Understand the Appeal Of PHP

WebReference.com: Working With Forms

PHPied.com: HiLiteMe.com updated

SecWatch.org: CJ Tag Board Multiple Parameter Handling PHP Code Injection Vulnerabilities

WebDevLogs.com: Which way to get the PHP self script name is the fastest?


Community Events







Don't see your event here?
Let us know!


code example database PEAR zendframework cakephp mysql ajax conference framework developer book releases application zend job package security release PHP5

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework