Vulnerabilities > CVE-2007-0566 - SQL Injection vulnerability in ASP News News_Detail.ASP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
asp-news
exploit available

Summary

SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Vulnerable Configurations

Part Description Count
Application
Asp_News
1

Exploit-Db

descriptionASP NEWS. CVE-2007-0566. Webapps exploit for asp platform
fileexploits/asp/webapps/3187.txt
idEDB-ID:3187
last seen2016-01-31
modified2007-01-24
platformasp
port
published2007-01-24
reporterajann
sourcehttps://www.exploit-db.com/download/3187/
titleASP NEWS <= 3.0 - news_detail.asp Remote SQL Injection Vulnerability
typewebapps