VulnerabilityModified
CVE-2006-5927
SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter.
HIGH 7.5EPSS 1.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- asp scripter/easy portal · asp scripter/live support
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22856Vendor Advisory
- http://securityreason.com/securityalert/1874
- http://www.securityfocus.com/archive/1/451370/100/0/threaded
- http://www.securityfocus.com/bid/21031
- http://www.vupen.com/english/advisories/2006/4499
- http://secunia.com/advisories/22856Vendor Advisory
- http://securityreason.com/securityalert/1874
- http://www.securityfocus.com/archive/1/451370/100/0/threaded
- http://www.securityfocus.com/bid/21031
- http://www.vupen.com/english/advisories/2006/4499
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.