vendor:
Ebay Clone 2009
by:
Moudi
7,5
CVSS
HIGH
Blind SQL Injection and XSS
89, 79
CWE
Product Name: Ebay Clone 2009
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: ebayclonescript.com/ebayclone2009
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Ebay Clone 2009 Multiple Remote Vulnerabilities
The vulnerability exists in the 'category.php' and 'search.php' files of the Ebay Clone 2009 script. An attacker can exploit the Blind SQL Injection vulnerability by sending a maliciously crafted HTTP request to the vulnerable script. An attacker can exploit the XSS vulnerability by sending a maliciously crafted HTTP request to the vulnerable script.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of the software.