vendor:
RV Dealer Website
by:
underground-stockholm.com
6,1
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: RV Dealer Website
Affected Version From: 1.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: CVE-2020-1234, CVE-2020-5678
CPE: a:micronetsoft:rv_dealer_website
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2020
MicroNetSoft RV Dealer Website Two SQL Injection Vulnerabilities
MicroNetSoft RV Dealer Website is vulnerable to two SQL injection vulnerabilities. The first vulnerability is located in the "selStock" parameter of the "search.asp" page and the second vulnerability is located in the "orderBy" parameter of the "showAlllistings.asp" page. Both of these parameters are vulnerable to SQL injection attacks.
Mitigation:
The vendor should patch the vulnerable code and ensure that all user input is properly sanitized and validated.