vendor:
Fancy Clone Script
by:
8bitsec
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Fancy Clone Script
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:pofitec:fancy_clone_script:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux 2.0, Mac OS 10.13.3
2018
Fancy Clone Script – ‘search_browse_product’ SQL Injection
SQL injection on [search_browse_product] POST parameter. The exploit uses boolean-based blind, error-based, AND/OR time-based blind and UNION query payloads.
Mitigation:
Input validation and sanitization should be done on the server-side to prevent SQL injection attacks.