vendor:
ASP-CMS
by:
Sina Yazdanmehr (R3d.W0rm)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: ASP-CMS
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:asp-cms:asp-cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
ASP-CMS v.1.0 Sql Injection Vulnerability
A vulnerability in ASP-CMS v.1.0 allows an attacker to inject malicious SQL commands into the application. This can be exploited to gain access to the application's database and potentially gain access to sensitive information. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'cha' parameter of the 'index.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands. This can be used to gain access to the application's database and potentially gain access to sensitive information.
Mitigation:
Input validation should be used to ensure that user-supplied input is properly sanitized. Additionally, the application should be configured to use parameterized queries to prevent SQL injection attacks.