vendor:
Harland Scripts 11 Products
by:
G4N0K
9,3
CVSS
HIGH
Remote Command Execution
N/A
CWE
Product Name: Harland Scripts 11 Products
Affected Version From: Traffic Click 4 Cash Script v1.0
Affected Version To: AD PHP Script v1.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Harland Scripts 11 Products Remote Command Execution Exploit
Harland Scripts 11 Products are vulnerable to Remote Command Execution. The vulnerable scripts are Traffic Click 4 Cash Script, Get A Date Script, Birthsake Keepsake, FFA, TShirt Rental Script, Mug Rental script, Top Hits, Recipe 6.0, Link Lister Traffic System, Link Back Checker Service Script and AD PHP Script. Some of these scripts are also vulnerable to SQL Injection and Arbitrary File Upload (Auth bypass).
Mitigation:
Developers should ensure that user input is properly sanitized and validated before being used in any command execution.