Vulnerabilities > CVE-2006-5879 - SQL Injection vulnerability in Aspportal 3.0.0/3.1.0/3.1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
aspportal
exploit available

Summary

SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbitrary SQL commands via the Poll_ID parameter, a different vector than CVE-2006-1353.

Vulnerable Configurations

Part Description Count
Application
Aspportal
4

Exploit-Db

descriptionASPPortal <= 4.0.0 (default1.asp) Remote SQL Injection Exploit. CVE-2006-5879. Webapps exploit for asp platform
fileexploits/asp/webapps/2762.asp
idEDB-ID:2762
last seen2016-01-31
modified2006-11-12
platformasp
port
published2006-11-12
reporterajann
sourcehttps://www.exploit-db.com/download/2762/
titleASPPortal <= 4.0.0 default1.asp Remote SQL Injection Exploit
typewebapps