PT-2005-2262 · Ipswitch · Ipswitch Whatsup Professional

Published

2005-06-22

·

Updated

2008-09-05

·

CVE-2005-1250

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: IpSwitch WhatsUp Professional 2005 SP1
Description: The issue concerns a SQL injection vulnerability in the logon screen of the web front end, specifically in NmConsole/Login.asp. This vulnerability allows remote attackers to execute arbitrary SQL commands by manipulating the sUserName or sPassword parameters in the User Name field or Password field, respectively.
Recommendations: For IpSwitch WhatsUp Professional 2005 SP1, consider restricting access to the logon screen of the web front end until a patch is available. As a temporary workaround, avoid using the sUserName and sPassword parameters in the affected API endpoint.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1250

Affected Products

Ipswitch Whatsup Professional