header-logo
Suggest Exploit
vendor:
Pilot Cart
by:
Ariko-Security
7,5
CVSS
HIGH
multiple SQL injections, multiple XSS, multiple iFrame injections, multiple link injections
89
CWE
Product Name: Pilot Cart
Affected Version From: 7.3
Affected Version To: 7.3
Patch Exists: NO
Related CWE: CVE-2008-2688
CPE: a:pilot_cart:pilot_cart:7.3
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010

ASPilot Pilot Cart 7.3 multiple vulnerabilities

Input passed via the "article" parameter to pilot.asp and kb.asp is not properly sanitised before being used in a SQL query. Input passed via the "specific" parameter to cart.asp is not properly sanitised before being used in a SQL query. Input passed via the "countrycode" parameter to contact.asp is not properly sanitised before being used in a SQL query. Input passed via the "srch" parameter to search.asp is not properly sanitised before being used in a SQL query. Input passed to the "countrycode" parameter in contact.asp is not properly sanitised before being returned to the user. Input passed to the "USERNAME" parameter in gateway.asp and cart.asp is not properly sanitised before being returned to the user. Input passed to the "specific" parameter in quote.asp and buyitnow.asp is not properly sanitised before being returned to the user.

Mitigation:

n/a
Source

Exploit-DB raw data: