Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-1250. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates SQL injection in WhatsUp Professional's login.asp script, allowing unauthorized password resets and privilege escalation via crafted input in the 'password' parameter.
Description
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).
Exploits (1)
This exploit demonstrates SQL injection in WhatsUp Professional's login.asp script, allowing unauthorized password resets and privilege escalation via crafted input in the 'password' parameter.