pfile Multiple Cross Site Scripting and SQL Injection Vulnerabilities

Summary
pfile is prone to a cross-site scripting vulnerability and an SQL- injection vulnerability because it fails to properly sanitize user- supplied input. Exploiting these issues could allow an attacker to steal cookie- based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. pfile 1.02 is vulnerable other versions may also be affected.
References