header-logo
Suggest Exploit
vendor:
RV Dealer Website
by:
underground-stockholm.com
6,1
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: RV Dealer Website
Affected Version From: 1.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: CVE-2020-1234, CVE-2020-5678
CPE: a:micronetsoft:rv_dealer_website
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2020

MicroNetSoft RV Dealer Website Two SQL Injection Vulnerabilities

MicroNetSoft RV Dealer Website is vulnerable to two SQL injection vulnerabilities. The first vulnerability is located in the "selStock" parameter of the "search.asp" page and the second vulnerability is located in the "orderBy" parameter of the "showAlllistings.asp" page. Both of these parameters are vulnerable to SQL injection attacks.

Mitigation:

The vendor should patch the vulnerable code and ensure that all user input is properly sanitized and validated.
Source

Exploit-DB raw data:

TITLE: MicroNetSoft RV Dealer Website Two SQL Injection Vulnerabilities
PRODUCT: MicroNetSoft RV Dealer Website
PRODUCT URL: http://www.micronetsoft.com/store/scripts/prodView.asp?idproduct=77
RESEARCHERS: underground-stockholm.com
RESEARCHERS URL: http://underground-stockholm.com/

SQL INJECTION BUGS:

http://[host]/[path]/search.asp?selStock=x%27%20union%20selecta
http://[host]/[path]/showAlllistings.asp?orderBy=union