7.5
CVSSv2

CVE-2006-2541

Published: 23/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote malicious users to execute arbitrary SQL commands via the layid parameter to (1) login.asp and (2) main.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

john andersson zixforum 1.12

Exploits

Zix Forum <= 112 (layid) SQL Injection Vulnerability Vulnerability: -------------------- SQL_Injection: Input passed to the "layid" parameter in 'settingsasp' not properly sanitised before being used in a SQL query This can be exploited to manipulate SQL queries by injecting arbitrary SQL code Successful exploitation extracts username and ...