Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2848

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-2848
Last Modified 05 Sep 2008 05:05:35
Published 06 Jun 2006 04:06:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2848

Summary

links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.

Vulnerable Systems

Application

  • Full Revolution Aspweblinks 2.0


References

BUGTRAQ - 20060602 aspWebLinks 2.0 Remote SQL Injection / Admin Pass Change Exploit

MILW0RM - 1859


Last Updated: 27 May 2016 10:42:46