Vulnerabilities > CVE-2007-4108 - SQL Injection vulnerability in Online Event Registration Template Sign_In.ASPX

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
codewidgets

Summary

SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.

Vulnerable Configurations

Part Description Count
Application
Codewidgets
1