vendor:
eCardMAX
by:
Zeroscience
7,5
CVSS
HIGH
SQL Injection and XSS
89 (SQL Injection) and 79 (XSS)
CWE
Product Name: eCardMAX
Affected Version From: 10.5
Affected Version To: 10.5
Patch Exists: Yes
Related CWE: N/A
CPE: a:ecardmax:ecardmax:10.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/2.2.26, PHP/5.3.28, MySQL/5.5.49-cll
2016
eCardMAX 10.5 SQL Injection and XSS Vulnerabilities
eCardMAX suffers from a SQL Injection vulnerability. Input passed via the 'row_number' GET parameter is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Multiple cross-site scripting vulnerabilities were also discovered. The issue is triggered when input passed via multiple parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
The vendor has released a patch to address the issue.