header-logo
Suggest Exploit
vendor:
PHP Stock Management System
by:
Ragha Deepthi K R
8,8
CVSS
HIGH
Persistent Cross Site Scripting
79
CWE
Product Name: PHP Stock Management System
Affected Version From: 1.02
Affected Version To: 1.02
Patch Exists: NO
Related CWE: N/A
CPE: a:posnic:php_stock_management_system:1.02
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014

Multiple Persistent Cross Site Scripting Vulnerabilities in PHP Stock Management System 1.02

PHP Stock Management System 1.02 is vulnerable for multiple Persistent Cross Site Scripting Vulnerabilities. The vulnerability affects 'sname'(Store Name Field), 'address'(Address Field), 'place'(Place Field), 'city'(City Field), pin(Pin Field), website(Website Field), email(Email Field) parameters while updating the store details in 'update_details.php' and when seen in 'view_report.php'

Mitigation:

Input validation and output encoding should be used to prevent XSS attacks.
Source

Exploit-DB raw data:

​# Exploit Title: Multiple Persistent Cross Site Scripting Vulnerabilities
in PHP Stock Management System 1.02
# Date: 25 Aug 2014
# Exploit Author: ​Ragha Deepthi K R
# Vendor Homepage: ​http://www.posnic.com/​
# Software Link:​ http://sourceforge.net/projects/stockmanagement/
# Version: ​1.02
# Tested on: Windows 7

#################################################
​PHP Stock Management System 1.02​ is vulnerable for ​multiple Persistent
Cross Site Scripting Vulnerabilit​ies.
The vulnerability affects 'sname'(Store Name Field), 'address'(Address
Field), 'place'(Place Field), 'city'(City Field), pin(Pin Field),
website(Website Field), email(Email Field) parameter​s​ while updating the
​store details in 'update_details.php' and when seen in 'view_report.php'

#################################################
Greetz :​ Syam !​