10
CVSSv2

CVE-2003-0560

Published: 18/08/2003 Updated: 18/10/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in shopexd.asp for VP-ASP allows remote malicious users to gain administrator privileges via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

virtual programming vp-asp 5.0

Exploits

source: wwwsecurityfocuscom/bid/8159/info It has been reported that VP-ASP does not sufficiently sanitize user input passed to the shopexdasp script contained in the software As a result, it may be possible for remote attackers to embed SQL commands which are to be passed to the underlying database engine #!/usr/bin/perl # PRIVATE***P ...
source: wwwsecurityfocuscom/bid/8159/info It has been reported that VP-ASP does not sufficiently sanitize user input passed to the shopexdasp script contained in the software As a result, it may be possible for remote attackers to embed SQL commands which are to be passed to the underlying database engine #!/usr/bin/perl -w $pamer = ...