creadirectory suffers from SQL injection and cross site scripting flaws.
639b5ed0017d44a33d9cbe06dacac2bd11cc744b4065f65d650910023bb61d3d
vendor site: http://www.creascripts.com/
product:creadirectory
bug: injection sql & xss
risk : medium
injection sql:
/search.asp?search=1&submit=Search&category='[sql]
xss:
/addlisting.asp?cat=[xss]
/search.asp?search=[xss]
laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit@gmail.com