Landshop v0.9.2 – Multiple Web Vulnerabilities
A remote SQL Injection vulnerability is detected on LandShops Web Application v0.9.2. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise. A remote Cross Site Scripting vulnerability is detected on LandShops Web Application v0.9.2. The vulnerability allows an attacker (remote) or local low privileged user account to inject own malicious script codes on the application side (persistent). Successful exploitation of the vulnerability results in session hijacking, client-side phishing attacks, malicious source code manipulation and application-side denial of service attacks.