Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AdMentor远程可插入SQL指令漏洞
Vulnerability Description
AdMentor是Stefan Holmberg创建的免费ASP脚本收集程序。 据报告,某些版本的AdMentor存在SQL Injection漏洞。在登录过程中远程用户输入的的内容被用来构造一个SQL查询语句,但是userid、pwd参数中单引号一类的特殊字符未被过滤掉。 攻击者利用该漏洞可以Admentor系统中任意用户身份登录而无需知道相应的口令。
CVSS Information
N/A
Vulnerability Type
N/A