|
Description
|
|
A new vulnerability was reported in ASPJar Guestbook, which can be exploited by an attacker to conduct SQL injection attacks. This flaw exists due to a missing input sanitising error when handling the "username" and "password" variables (admin/login.asp), which could be exploited by a remote attacker to inject SQL commands and be authenticated as the administrator.
|