SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and previous versions, (2) Journal 1.0 and previous versions, (3) Polls 3.06 and previous versions, and (4) and Database Login 1.71 and previous versions allows remote malicious users to execute arbitrary SQL commands via the txtUserName parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
webwiz site news |
||
webwiz journal |
||
webwiz database login |
||
webwiz weekly poll |
||
webwiz site news 2.00 |