vendor:
VP-ASP
by:
SecurityFocus
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: VP-ASP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
VP-ASP SQL Injection Vulnerability
It has been reported that VP-ASP may be prone to a SQL injection vulnerability that may allow an attacker to disclose sensitive information by supplying malicious SQL code to the underlying database. The problem exists in the 'shopdisplayproducts.asp' script of the software.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized before being used in SQL queries.