vendor:
My Directory
by:
Özkan Mustafa Akkus (AkkuS)
7.5
CVSS
HIGH
SQL Injection/Cross-Site Scripting
89, 79
CWE
Product Name: My Directory
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:codecanyon:my_directory
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
My Directory 2.0 – SQL Injection / Cross-Site Scripting
The vulnerability allows an attacker to inject sql commands from the user search section with 'business' parameter. Another parameter 'city', has XSS vulnerability.
Mitigation:
Input validation and sanitization should be done for user input.