CVE-2009-2604

Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:zenhelpdesk:zen_help_desk:2.1:*:*:*:*:*:*:*

Information

Published : 2009-07-27 07:30

Updated : 2017-09-18 18:29


NVD link : CVE-2009-2604

Mitre link : CVE-2009-2604


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

zenhelpdesk

  • zen_help_desk