Summary
GeoClassifieds Lite is prone to multiple SQL-injection and cross-site scripting vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie- based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
GeoClassifieds Lite 2.0.1, 2.0.3.1, 2.0.3.2 and 2.0.4 are vulnerable
other versions may also be affected.
References
Updated on 2015-03-25
Severity
Classification
-
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Allegro RomPager `Misfortune Cookie` Vulnerability
- AlienVault OSSIM SQL Injection and Remote Code Execution Vulnerabilities
- appRain CMF SQL Injection And Cross Site Scripting Vulnerabilities
- AV Arcade 'ava_code' Cookie Parameter SQL Injection Vulnerability
- Ad Manager Pro Multiple SQL Injection And XSS Vulnerabilities