Heap
01-02-08, 22:46
Multiple SQL injection vulnerabilities in Pre Dynamic Institution allow remote attackers to execute arbitrary SQL commands via the (1) sloginid and (2) spass parameters to (a) login.asp and (b) siteadmin/login.asp. NOTE: some of these details are obtained from third party information.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0543)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0543)