vendor:
VehicleWorkshop
by:
Mehran Feizi
9.0
CVSS
HIGH
SQL Injection
89
CWE
Product Name: VehicleWorkshop
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:spiritson:vehicleworkshop
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
VehicleWorkshop 1.0 – ‘bookingid’ SQL Injection
VehicleWorkshop 1.0 is vulnerable to SQL Injection. The vulnerability exists due to user-supplied input to the 'bookingid' parameter in '/viewtestdrive.php' not being properly sanitized before being used in SQL queries. An attacker can leverage this vulnerability to execute arbitrary SQL commands in the context of the application's database user.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized before being used in SQL queries.