cve/2006/CVE-2006-2887.md
2024-05-26 14:27:05 +02:00

669 B

CVE-2006-2887

Description

Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.

POC

Reference

Github

No PoCs found on GitHub currently.