PT-2006-7146 · Appintellect · Appintellect Spotlight Crm

Ajann

·

Published

2006-12-14

·

Updated

2017-10-19

·

CVE-2006-6543

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AppIntellect SpotLight CRM version 1.0
Description The issue concerns SQL injection vulnerabilities in the login.asp file. Remote attackers can execute arbitrary SQL commands by manipulating the UserName and possibly the password parameter.
Recommendations For AppIntellect SpotLight CRM version 1.0, consider restricting access to the login.asp file until a patch is available. As a temporary workaround, avoid using the UserName and password parameters in the login endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6543

Affected Products

Appintellect Spotlight Crm