vendor:
Car Portal CMS
by:
Vulnerability Laboratory Research Team
6,4
CVSS
MEDIUM
Persistent Input Validation Vulnerabilities
20
CWE
Product Name: Car Portal CMS
Affected Version From: Car Portal v3.0
Affected Version To: Car Portal v3.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Car Portal CMS v3.0 – Multiple Web Vulnerabilities
Multiple persistent input validation vulnerabilities are detected in the car portal v3.0 web application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Successful exploitation of the vulnerability can lead to session hijacking (manager/admin) or stable (persistent) context manipulation. Exploitation requires low user interaction.
Mitigation:
Edit the source code to ensure that input is properly sanitized.