Security Advisory

CVE-2005-1250

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-06-22 04:00:00
Last updated 2024-08-07 21:44:05
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).