Release date: 2011-12-17
Updated on: 2012-11-01
Affected Systems:
2 daybiz Video Community Portal
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51107
2 daybiz Social Community site PHP scripts are online Social network software.
Social Network Community 2 and other versions have security vulnerabilities that allow attackers to control applications, access or modify data, and exploit other vulnerabilities in lower-level databases.
<* Source: Lazmania61
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/social2/user.php? UserId = 12 & #39;
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
2 daybiz
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.2daybiz.com/