SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
References
Configurations
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/10659 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/3346 - | |
References | () http://securitytracker.com/id?1008745 - | |
References | () http://www.osvdb.org/3585 - | |
References | () http://www.pensacolawebdesigns.com/xtremeasp/readmore.asp - Patch | |
References | () http://www.securityfocus.com/archive/1/350028/30/21640/threaded - | |
References | () http://www.securityfocus.com/bid/9438 - | |
References | () http://www.tripbit.org/advisories/TA-150104.txt - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/14860 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:54
NVD link : CVE-2004-2746
Mitre link : CVE-2004-2746
CVE.ORG link : CVE-2004-2746
JSON object : View
Products Affected
pensacola_web_designs
- xtremeasp_photogallery
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')