Vulnerabilities > CVE-2006-2848 - Remote Security Bypass vulnerability in Full Revolution Aspweblinks 2.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
full-revolution
exploit available

Summary

links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.

Vulnerable Configurations

Part Description Count
Application
Full_Revolution
1

Exploit-Db

descriptionaspWebLinks 2.0 Remote SQL Injection / Admin Pass Change Exploit. CVE-2006-2847,CVE-2006-2848. Webapps exploit for asp platform
fileexploits/asp/webapps/1859.html
idEDB-ID:1859
last seen2016-01-31
modified2006-06-01
platformasp
port
published2006-06-01
reporterajann
sourcehttps://www.exploit-db.com/download/1859/
titleaspWebLinks 2.0 - Remote SQL Injection / Admin Pass Change Exploit
typewebapps