CVE-2006-5217 Information

Description

SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp also known as the Kullanici Adi (k_a) and Sifre (sifre) parameters.

Reference

http://securityreason.com/securityalert/1700 http://www.securityfocus.com/archive/1/447914/100/0/threaded http://www.securityfocus.com/bid/20378 https://exchange.xforce.ibmcloud.com/vulnerabilities/29380

Share on: