Record summary

CVE-2017-1000474 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBVehicle Sales Management System - Multiple VulnerabilitiesExploitDB exploitby SingNot analyzed1 file
ExploitDB

PoC details

References

3