7.5
CVSSv2

CVE-2005-1250

Published: 22/06/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote malicious users to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch whatsup professional_2005_sp1

Exploits

source: wwwsecurityfocuscom/bid/14039/info WhatsUp Professional is prone to an SQL injection vulnerability affecting its Web-based front end This issue is due to a failure in the application to properly sanitize user-supplied input to the 'loginasp' script before using it in an SQL query Successful exploitation could result in a compr ...