7.5
CVSSv2

CVE-2018-5986

Published: 24/01/2018 Updated: 19/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.

Vulnerable Product Search on Vulmon Subscribe to Product

easycarscript easycarscript 2014

Exploits

# # # # # # Exploit Title: Easy Car Script 2014 - SQL Injection # Dork: N/A # Date: 23012018 # Vendor Homepage: wwweasyphotostorecom/ # Software Link: wwweasycarscriptcom/ # Version: 2014 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE-2018-5986 # # # # # # Exploit Author: Ihsan Sencan # Author Web: ih ...
Easy Car Script version 2014 suffers from a remote SQL injection vulnerability ...