First published: Wed Jun 22 2005(Updated: )
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IpSwitch WhatsUp | =professional_2005_sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.