|
|
Info |
Last Modified |
| 11 months ago |
|
|
|
|
Description |
VP-ASP software suite is vulnerable to a SQL injection bug which may allow an attacker to execute arbitrary SQL commands. The flaw is found in the shopexd.asp script. This allows an attacker access to sensitive information, create new users and elevate privileges.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 5.0 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: The vendor has suggested the administration page be moved to an unpredictable location. From VP-ASP 3.0 and higher set the following in shop$config.asp:
const xAdminPage="youradminpagename.asp" const xShowAdmin="No"
|
|
Products |
|
VP-ASP
 |
4.0 |
|
|
|
|
Tools & Filters |
|
Nikto
|
1450
1451
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|