PT-2005-2165 · Acnews · Acnews

Published

2005-04-13

·

Updated

2008-09-05

·

CVE-2005-1149

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ACNews version 1.0
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is possible via the username or password parameters in the admin/login.asp file.
Recommendations For ACNews version 1.0, consider temporarily restricting access to the admin/login.asp file until a patch is available. As a mitigation measure, avoid using the username and password parameters in the affected file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1149

Affected Products

Acnews