vendor:
NetClassifieds
by:
Unknown
7.5
CVSS
HIGH
Input Validation
20
CWE
Product Name: NetClassifieds
Affected Version From: NetClassifieds Free, Standard, Professional, and Premium editions
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Not mentioned
CPE: a:netclassifieds:netclassifieds
Platforms Tested: Unknown
Unknown
NetClassifieds Multiple Input-Validation Vulnerabilities
NetClassifieds is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input. These vulnerabilities include multiple SQL-injection issues and cross-site scripting issues. A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Mitigation:
The vendor should sanitize user-supplied input to prevent SQL-injection and cross-site scripting vulnerabilities. Regular security updates and patches should be applied.