9.8
CVSSv3

CVE-2017-1000474

Published: 24/01/2018 Updated: 23/03/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.

Vulnerable Product Search on Vulmon Subscribe to Product

vehicle sales management system project vehicle sales management system 2017-07-30

Exploits

# Exploit Title: VSMS Multiple Vulnerabilities # Google Dork: N/A # Date: 16-3-2018 # Exploit Author: Sing # Vendor Homepage: sourceforgenet/projects/vsms-php/?source=typ_redirect # Software Link: sourceforgenet/projects/vsms-php/?source=typ_redirect # Version: 07/2017 (possible v12) # Tested on: CentOS 69 # CVE : CVE-2017-10004 ...
Vehicle Sales Management System suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities ...