Vulnerabilities > CVE-2007-4208 - SQL Injection vulnerability in Next Gen Portfolio Manager Default.ASP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
morgan-ids
exploit available

Summary

SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action.

Vulnerable Configurations

Part Description Count
Application
Morgan_Ids
1

Exploit-Db

descriptionNext Gen Portfolio Manager Default.ASP Multiple SQL Injection Vulnerabilities. CVE-2007-4208. Webapps exploit for asp platform
idEDB-ID:30451
last seen2016-02-03
modified2007-08-03
published2007-08-03
reporterAria-Security Team
sourcehttps://www.exploit-db.com/download/30451/
titleNext Gen Portfolio Manager Default.ASP Multiple SQL Injection Vulnerabilities