7.5
CVSSv2

CVE-2008-5974

Published: 27/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) password and (2) username fields.

Vulnerable Product Search on Vulmon Subscribe to Product

activewebsoftwares active price comparison 4.0

Exploits

[~] ----------------------------بسم الله الرحمن الرحيم------------------------------ [~]Tybe:(Auth Bypass) Remote SQL Injection Vulnerability [~]Vendor: wwwactivewebsoftwarescom [~]Software: Active Web Mail v 4 [~]author: ((я3d D3v!L)) [~] Date: 28112008 ...
[~] ----------------------------بسم الله الرحمن الرحيم------------------------------ [~]Tybe:(Auth Bypass) Remote SQL Injection Vulnerability [~]Vendor:wwwactivewebsoftwarescom [~]Software: Active Price Comparison v 4 [~]author: ((я3d D3v!L)) [~] Date: 2811 ...