vendor:
Telephone Directory 2008
by:
CWH Underground
8.8
CVSS
HIGH
SQL Injection and Reflected XSS
89 (SQL Injection) and 79 (Cross-site Scripting)
CWE
Product Name: Telephone Directory 2008
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Telephone Directory 2008 (SQL/XSS) Multiple Remote Vulnerabilities
Telephone Directory 2008 is vulnerable to SQL Injection and Reflected XSS. An attacker can exploit these vulnerabilities to gain access to the database and execute malicious scripts in the user's browser.
Mitigation:
To mitigate SQL Injection, use parameterized queries and input validation. To mitigate XSS, use a web application firewall and input validation.