First published: Wed Jan 31 2007(Updated: )
SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getvera Vera Edge | <=1.3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0632 is considered a moderate severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2007-0632, update your ASP EDGE software to version 1.3b or later, which addresses this SQL injection vulnerability.
Attackers can exploit CVE-2007-0632 to execute arbitrary SQL commands against the database, potentially leading to data breach or corruption.
CVE-2007-0632 affects ASP EDGE versions up to and including 1.3a.
Mitigating CVE-2007-0632 without upgrading may be difficult, but employing input validation and sanitization could help reduce risk.