vendor:
Ebay Clone 2009
by:
MizoZ [EvilWay Team]
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Ebay Clone 2009
Affected Version From: Ebay Clone 2009
Affected Version To: Ebay Clone 2009
Patch Exists: NO
Related CWE: N/A
CPE: ebayclonescript.com/ebayclone2009/
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Ebay Clone 2009 Multiple SQL Injection Vulnerabilities
Multiple SQL Injection vulnerabilities were discovered in Ebay Clone 2009. The first vulnerability is located in the 'feedback.php' file with the 'user_id' parameter. The second vulnerability is located in the 'view_full_size.php' file with the 'item_id' parameter. The third vulnerability is located in the 'classifide_ad.php' file with the 'item_id' parameter. The fourth vulnerability is a Blind SQL Injection located in the 'crosspromoteitems.php' file with the 'item_id' parameter.
Mitigation:
Input validation should be used to prevent SQL Injection attacks.