Summary
Family Connections is prone to multiple input-validation vulnerabilities, including a local file-include issue, an arbitrary file-upload issue, and multiple SQL-injection issues. These issues occur because the application fails to properly sanitize user- supplied input.
Exploiting these issues may allow an unauthorized user to view files and execute local scripts, execute arbitrary script code, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Family Connections versions 2.1.3 and prior are affected.
References
Updated on 2015-03-25