Secunia Security Advisory – Some vulnerabilities have been reported in Basic Analysis and Security Engine, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks. 1) Some input isn’t properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. This is related to: SA17314 2) Some input isn’t properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/41561/sa17523.txt
Source: https://packetstormsecurity.com/files/41561/Secunia-Security-Advisory-17523.html

