CVE-2006-2848
aspWebLinks 2.0 - Unauthenticated Administrative Password Change via txtAdministrativePassword Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2848. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in aspWebLinks 2.0, allowing an attacker to retrieve the administrative password via a crafted URL. It also includes an HTML form to change the admin password by submitting a POST request to the vulnerable endpoint.
Description
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in aspWebLinks 2.0, allowing an attacker to retrieve the administrative password via a crafted URL. It also includes an HTML form to change the admin password by submitting a POST request to the vulnerable endpoint.