AOH :: HP Unsorted C :: B06-5758.HTM

Car Site Manager



Car Site Manager
Car Site Manager



Car Site Manager [injection sql & xss (get)]
vendor site:http://www.mginternet.com/ 
product:Car Site Manager
bug:injection sql
risk:medium

injection sql :
http://site.com/csm/asp/detail.asp?l=&p='[sql] 
http://site.com/csm/asp/listings.asp?l='[sql] 
http://site.com/csm/asp/listings.asp?s=search&typ='[sql] 
http://site.com/csm/asp/listings.asp?s=search&typ=4&loc='[sql] 

xss (get):
 


laurent gaffi=E9 & benjamin moss=E9
http://s-a-p.ca/ 
contact: saps.audit@gmail.com 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.