PT-2006-1681 · Whomp · Whomp Real Estate Manager Xp
Night_Warrior771
·
Published
2006-02-09
·
Updated
2018-10-19
·
CVE-2006-0624
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Whomp Real Estate Manager XP version 2005
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
username and password parameters in the "check.asp" endpoint.Recommendations
For Whomp Real Estate Manager XP version 2005, consider restricting access to the check.asp endpoint until a fix is available. As a temporary workaround, avoid using the
username and password parameters in this endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Whomp Real Estate Manager Xp