CVE-2008-5974 Information

Description

Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.

Reference

http://secunia.com/advisories/32921 http://www.vupen.com/english/advisories/2008/3296 https://exchange.xforce.ibmcloud.com/vulnerabilities/46909 https://www.exploit-db.com/exploits/7283

Share on: