7.5
CVSSv2

CVE-2005-1149

Published: 13/04/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote malicious users to execute arbitrary SQL commands via the (1) username or (2) password parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

# wwwgooglecom/search?hl=en&lr=&q=acnews+10+loginasp&btnG=Search # /str0ke Product:ACNews version :10 VULNERABILITY CLASS: SQL injection [exploit] Log in with username:' or 'x'='x password :' or 'x'='x from admin/loginasp page greetz to HaXoR & LOverboy auther : LaMeR securitygurus team # milw0rmcom [2005-04-09] ...