CVE-2017-1000474
CRITICALSoyket Chowdhury Vehicle Sales Management System 2017-07-30 - RCE
Title source: llmDescription
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0259
EPSS Percentile
85.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
vehicle_sales_management_system_project/vehicle_sales_management_system
2017-07-30
Published
Jan 24, 2018
Tracked Since
Feb 18, 2026