>> Blue Smiley Organizer Unspecified SQL Injection and File Upload Vulnerabilities
Title : Blue Smiley Organizer Unspecified SQL Injection and File Upload Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3958 CVE ID : CVE-2006-5237 - CVE-2006-5238
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-09
Technical Description
Multiple vulnerabilities have been identified in Blue Smiley Organizer, which could be exploited by remote attackers to compromise a vulnerable server.
The first issue is due to unspecified input validation errors in various scripts that do not validate certain parameters, which could be exploited by malicious people to conduct SQL injection attacks.
The second vulnerability is due to an unspecified error in the file upload module.