Vulnerabilities
Vulnerable Software
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.
CVSS Score
7.5
EPSS Score
0.007
Published
2008-12-15
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.
CVSS Score
5.0
EPSS Score
0.035
Published
2008-12-15


Contact Us

Shodan ® - All rights reserved