CVE-2008-5926
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka user field) or the (2) password parameter (aka pass field).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka user field) or the (2) password parameter (aka pass field). NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- asp-dev/internal e-mail system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33103Vendor Advisory
- http://securityreason.com/securityalert/4925
- http://www.securityfocus.com/bid/32808Exploit
- https://www.exploit-db.com/exploits/7447
- http://secunia.com/advisories/33103Vendor Advisory
- http://securityreason.com/securityalert/4925
- http://www.securityfocus.com/bid/32808Exploit
- https://www.exploit-db.com/exploits/7447
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.