vendor:
Auto Dealer Script
by:
bi0
8.8
CVSS
HIGH
Persistent XSS / SQL Backup
79
CWE
Product Name: Auto Dealer Script
Affected Version From: 5
Affected Version To: 5
Patch Exists: No
Related CWE: N/A
CPE: cpe:a:accscripts:auto_dealer_script
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Acc Auto Dealer Script [ Persistent XSS / SQL backup ]
Acc Auto Dealer Script is vulnerable to persistent XSS and SQL Backup. An attacker can inject malicious JavaScript code into the Description field of the user profile, which will be executed when the site admin visits the user profile. Additionally, the attacker can access the SQL backup file which contains user credentials.
Mitigation:
The application should validate user input and filter out any malicious code.