CVE-2005-3852 Information

Description

SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

Reference

http://pridels0.blogspot.com/2005/11/owos-lite-30-sql-inj.html http://secunia.com/advisories/17711 http://www.osvdb.org/21116 http://www.vupen.com/english/advisories/2005/2584

Share on: