vendor:
Businesses For Sale Listings
by:
L0rd CrusAd3r aka VSN
7,5
CVSS
HIGH
SQL injection
89
CWE
Product Name: Businesses For Sale Listings
Affected Version From: FSBO
Affected Version To: FSBO
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Site2nite Businesses For Sale Listings SQL injection
List businesses for sale by owner and broker at prices you determine. 8 pics per listing, advanced Search, detailed listings, full admin control panel. After sales support at no charge. Code: ASP 3.0 & VBScri. The vulnerability is present in the detail.asp page, where the ID parameter is vulnerable to SQL injection.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.