vendor:
Tradingeye
by:
Raghavendra Karthik D
8.8
CVSS
HIGH
Authentication Bypass and Reflected XSS
89, 79
CWE
Product Name: Tradingeye
Affected Version From: v6
Affected Version To: v6
Patch Exists: YES
Related CWE: N/A
CPE: tradingeye
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Tradingeye Multiple Vulnerabilities
Attackers can use Authentication Bypass to get into Admin Panel in the site. Reflected XSS Vulnerability in admin panel(search field) Exploit: ">><marquee><h1>XSSed_by_r007k17</h1></marquee>
Mitigation:
Input validation and sanitization, use of prepared statements, and proper authentication and authorization.