7.5
CVSSv2

CVE-2007-1566

Published: 21/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote malicious users to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.

Vulnerable Product Search on Vulmon Subscribe to Product

netvios netvios

Exploits

******************************************************************************* # Title : NetVios Portal (pageasp) Remote SQL Injection Vulnerability # Author : parad0x # Contact : :( # DPage : wwwscriptatynet/netvios-portalhtml # $$ : Free #SPage : wwwnetvioscom ************************************************** ...
******************************************************************************* # Title : NetVios <= 20 [News Application] (pageasp) Remote SQL Injection Vulnerability # Author : ajann ******************************************************************************* ###[target]/[path]//pageasp?NewsID=[SQL] Example: //pageasp?New ...