PT-2002-2640 · Vp Asp · Vp-Asp

Publicado

2002-12-31

·

Atualizado

2009-04-11

·

CVE-2002-1919

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VP-ASP version 4.0
Description The issue allows remote attackers to execute arbitrary SQL commands and bypass authentication. This can be achieved via the username or password fields in the shopadmin.asp file.
Recommendations For VP-ASP version 4.0, update the shopadmin.asp file to properly sanitize input in the username and password fields to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the shopadmin.asp file until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1919

Produtos afetados

Vp-Asp