CVE-2004-1553
CVE-2004-1553
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.
Productos afectados
n/a · n/aPoCs públicas encontradas — 2
cve_referencewww.exploit-db.com/exploits/6420no verificadocve_referencewww.exploit-db.com/exploits/6357no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://marc.info/?l=bugtraq&m=109604910025090&w=2http://osvdb.org/47913http://osvdb.org/47914http://secunia.com/advisories/31649https://exchange.xforce.ibmcloud.com/vulnerabilities/17507https://exchange.xforce.ibmcloud.com/vulnerabilities/44876https://exchange.xforce.ibmcloud.com/vulnerabilities/44877https://www.exploit-db.com/exploits/6357https://www.exploit-db.com/exploits/6420http://www.securityfocus.com/bid/11246http://www.securityfocus.com/bid/30996