vendor:
AutoDealer
by:
Sid3^effects aKa HaRi
8,8
CVSS
HIGH
MSSQLi
89
CWE
Product Name: AutoDealer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
MSSQLi Vulnerability
AutoDealer is an application ideal for the small or independent new or used car dealer who needs a way to display and update their inventory online. Backend by Access database, AutoDealer can store thousands of vehicles in categories with images. The exploit is present in two versions, Ver.1 http://server/Auto1/type.asp?iType=[ur injection code] and Ver.2 http://server/auto2/auto2/detail.asp?iPro=[ur injection code]
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.