vendor:
Open Auto Classifieds
by:
MorningStar Security
8,3
CVSS
HIGH
SQL Injection, Insecure File Upload, Cross Site Scripting, Filepath Disclosure
89, 79, 79, 200
CWE
Product Name: Open Auto Classifieds
Affected Version From: Open Auto Classifieds versions <= 1.5.9
Affected Version To: Open Auto Classifieds versions >= 1.6.0
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Multiple security issues in Open Auto Classifieds
Open Auto Classifieds is a vehicle listings manager that is popular with car dealer websites. It's written in PHP + MySQL and is available free at http://openautoclassifieds.com/. Multiple vulnerabilities exist in Open Auto Classifieds. These vulnerabilities can be exploited to allow access to read any information from the database, attack web browser clients through the web site, disclose the file path of the application and execute any arbitrary command on the web server.
Mitigation:
Upgrade, or apply the code fixes shown wihtin the advisory.