Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mfoxhacker

#37205of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2006-1269
7.5
2006-01-13
Aspsurvey · Aspsurvey · CVE-2006-0192
**Name of the Vulnerable Software and Affected Versions** ASPSurvey version 1.10 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `Password` parameter to the "login.asp" endpoint. **Recommendations** For ASPSurvey version 1.10, consider restricting access to the "login.asp" endpoint until a patch is available, and avoid using the `Password` parameter in this endpoint to minimize the risk of exploitation.