PoC Index

CVE-2005-1250

HIGH 7.5EPSS 20.9%

SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
20.86% chance of exploitation in the next 30 days, 97th percentile
Published
2005-06-22
Updated
2024-08-07

ExploitDB entries (1)

References

Related