vendor:
Kamads classifieds V2
by:
Mr.tro0oqy
7,5
CVSS
HIGH
Multiple Vulnerabilities
N/A
CWE
Product Name: Kamads classifieds V2
Affected Version From: V2
Affected Version To: V2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Kamads classifieds V2 Multiple Vulnerabilities
Kamads classifieds V2 is vulnerable to multiple vulnerabilities. An attacker can exploit these vulnerabilities to gain access to the admin panel of the application. The attacker can use the dork 'inurl:V2A_XHTML' to find vulnerable websites. The attacker can then use the exploit code 'javascript:document.cookie="$ja=$ja2;path=/";' to gain access to the admin panel.
Mitigation:
The application should be updated to the latest version to patch the vulnerabilities.