Vulnerabilities > CVE-2002-1919 - SQL Injection vulnerability in Virtual Programming Vp-Asp 4.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
virtual-programming
nessus

Summary

SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.

Vulnerable Configurations

Part Description Count
Application
Virtual_Programming
1

Nessus

NASL familyCGI abuses
NASL idVP-ASP_SQL_INJECTION.NASL
descriptionThe remote host is using the VP-ASP software suite. This set of CGIs is vulnerable to a SQL injection bug which may allow an attacker to take the control of the server as an administrator. From there, he can obtain the list of customers, steal their credit card information and more. In addition to this, this software is vulnerable to various file disclosure and cross-site scripting flaws.
last seen2020-06-01
modified2020-06-02
plugin id11786
published2003-07-08
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11786
titleVP-ASP shopexd.asp catalogid Parameter SQL Injection