Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Virtual Programming VP-ASP可插入SQL命令漏洞
Vulnerability Description
Virtual Programming VP-ASP是一款商业性质的电子购物应用系统,由ASP脚本编写。 Virtual Programming VP-ASP的登录脚本对用户提交的输入没有很好的过滤,可导致远程攻击者绕过验证访问系统。 Virtual Programming VP-ASP中的登录脚本对用户提交的输入在用于SQL查询时缺少过滤,攻击者提交非正常的数据就可以导致修改SQL查询而绕过访问控制,直接以管理员权限访问VP-ASP系统。
CVSS Information
N/A
Vulnerability Type
N/A