SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/439521/100/0/threaded | mailing list |
http://www.osvdb.org/27067 | vdb entry |
http://www.securityfocus.com/archive/1/439614/100/0/threaded | mailing list |
http://secunia.com/advisories/20985 | third party advisory |
http://www.securityfocus.com/bid/18897 | vdb entry |
http://www.kapda.ir/advisory-355.html | vendor advisory |
http://www.vupen.com/english/advisories/2006/2714 | vdb entry |
http://securityreason.com/securityalert/1206 | third party advisory |