CVE-2007-6138 Information

Description

SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information.

Reference

http://aria-security.net/forum/showthread.php?t=447 http://osvdb.org/38807 http://secunia.com/advisories/27758 http://www.securityfocus.com/archive/1/484021/100/0/threaded http://www.securityfocus.com/bid/26522 http://www.vupen.com/english/advisories/2007/3966

Share on: