vendor:
Spaceacre
by:
XroGuE
8,8
CVSS
HIGH
SQL/XSS/HTML Injection
89, 79, 80
CWE
Product Name: Spaceacre
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Spaceacre (SQL/XSS/HTML) Injection Vulnerabilities
Spaceacre is vulnerable to SQL/XSS/HTML injection. An attacker can inject malicious SQL/XSS/HTML code into the vulnerable parameters of the application. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code, to disclose sensitive information from the database, to execute arbitrary HTML and script code in the browser of the victim, to bypass authentication and authorization mechanisms, and to perform a wide range of other malicious activities.
Mitigation:
Input validation should be used to prevent SQL/XSS/HTML injection attacks. The application should also be configured to use the least privileged account with the least privileges necessary to perform its function.