vendor:
PetRatePro
by:
DaOne (@LibyanCA)
7,5
CVSS
HIGH
Remote Add Admin, SQL Injection, Remote File Upload
89, 89, 434
CWE
Product Name: PetRatePro
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Auxilium PetRatePro Multiple Vulnerabilities
Auxilium PetRatePro is vulnerable to Remote Add Admin, SQL Injection and Remote File Upload. An attacker can exploit the Remote Add Admin vulnerability by creating a new administrator account by submitting a malicious form. The SQL Injection vulnerability can be exploited by passing malicious payloads to the 'phid' parameter of the 'viewcomments.php' page. The Remote File Upload vulnerability can be exploited by uploading a malicious file to the 'upload_banners.php' page.
Mitigation:
Input validation should be performed on all user-supplied data. The application should also be configured to reject files with suspicious extensions. Access to the application should be restricted to trusted users.