Vulnerabilities > CVE-2004-2326 - SQL Injection vulnerability in IP3 Networks products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ip3-networks
exploit available

Summary

SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34.

Exploit-Db

descriptionIP3 Networks IP3 NetAccess Appliance SQL Injection Vulnerability. CVE-2004-2326. Remote exploit for hardware platform
idEDB-ID:23808
last seen2016-02-02
modified2004-03-12
published2004-03-12
reporterSyam Yanuar
sourcehttps://www.exploit-db.com/download/23808/
titleIP3 Networks IP3 NetAccess Appliance SQL Injection Vulnerability