vendor:
Pooya Site Builder (PSB)
by:
AmnPardaz Security Research Team
7.5
CVSS
HIGH
SQL Injection
89 (SQL Injection)
CWE
Product Name: Pooya Site Builder (PSB)
Affected Version From: 6.0 (Assembly Version)
Affected Version To: 6.0 (Assembly Version)
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Internet Explorer (IE)
N/A
Pooya Site Builder (PSB) SQL Injection Vulnerabilities
Pooya site builder (psb) is an easy to use database driven web content management and security management system. It allows you to create, edit & web content instantly using just a browser, psb provides all essential feature you need for running your own business websites (you can even use it for large websites, without the complexity of unused functions). SQL Injection in "/utils/getXsl.aspx" in "xslIdn" parameter, "/utils/getXml.aspx" in "part" parameter and "/utils/getXls.aspx" in "part" parameter. Use Internet Explorer (IE) for best result. ' used to bypass any SQL Injection denier.
Mitigation:
N/A