7.5
CVSSv2

CVE-2004-2746

Published: 31/12/2004 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote malicious users to execute arbitrary SQL commands via the (1) username and (2) password parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

pensacola web designs xtremeasp photogallery 2.0

Exploits

source: wwwsecurityfocuscom/bid/9438/info XtremeASP PhotoGallery is prone to an SQL injection vulnerability The issue is reported to exist in the administration login interface, which does not sufficiently sanitize user-supplied input for username and password values before including it in SQL queries This could permit remote attackers ...