vendor:
Barter Sites
by:
Not Specified
N/A
CVSS
N/A
SQL Injection & Persistent XSS
89, 79
CWE
Product Name: Barter Sites
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE: Not yet assigned
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla
2011
Barter Sites 1.3 Component Joomla SQL Injection & Persistent XSS vulnerabilities
Two vulnerabilities discovered - Category_id Parameter SQL injection and XSS in several places. The SQL injection can be exploited by passing malicious SQL code in the category_id parameter. The XSS can be exploited by posting malicious code in the Listing Title field when creating a new listing or in the Search field when searching for listings. The XSS can be viewed without being registered.
Mitigation:
No solution available.