PT-2005-2867 · Wwweb Concepts · Wwweb Concepts Events System

Published

2005-06-05

·

Updated

2024-02-14

·

CVE-2005-1910

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WWWeb Concepts Events System version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands via the password variable in the login.asp file. This can lead to unauthorized access and manipulation of database content.
Recommendations For WWWeb Concepts Events System version 1.0, consider validating and sanitizing user input for the password variable to prevent SQL injection attacks. As a temporary workaround, restrict access to the login.asp file until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2005-1910

Affected Products

Wwweb Concepts Events System