PT-2002-2640 · Vp Asp · Vp-Asp
Publicado
2002-12-31
·
Atualizado
2009-04-11
·
CVE-2002-1919
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VP-ASP version 4.0
Description
The issue allows remote attackers to execute arbitrary SQL commands and bypass authentication. This can be achieved via the
username or password fields in the shopadmin.asp file.Recommendations
For VP-ASP version 4.0, update the shopadmin.asp file to properly sanitize input in the
username and password fields to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the shopadmin.asp file until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vp-Asp