PT-2005-4671 · Asp · Asp-Rider
Published
2005-12-01
·
Updated
2018-10-19
·
CVE-2005-3931
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ASP-Rider version 1.6
Description
A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the HTTP referer.
Recommendations
For ASP-Rider version 1.6, consider restricting access to the default.asp file until a patch is available. As a temporary workaround, validate and sanitize all input to prevent malicious SQL commands from being executed.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asp-Rider