Back
CVE-2005-1250
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).
Published: Jun 22, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| ipswitch | whatsup | professional_2005_sp1 |
GitHub Security Advisory GHSA-h22c-f46h-xp6v
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for...
References (8)
- http://secunia.com/secunia_research/2005-13/advisory/
- http://www.corsaire.com/advisories/c050323-001.txt
- http://www.idefense.com/application/poi/display?id=268&type=vulnerabilities Patch, Vendor Advisory
- http://www.ipswitch.com/forums/shwmessage.aspx?ForumID=20&MessageID=7699 Patch, Vendor Advisory
- http://secunia.com/secunia_research/2005-13/advisory/
- http://www.corsaire.com/advisories/c050323-001.txt
- http://www.idefense.com/application/poi/display?id=268&type=vulnerabilities Patch, Vendor Advisory
- http://www.ipswitch.com/forums/shwmessage.aspx?ForumID=20&MessageID=7699 Patch, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
20.86%
Top 3% most likely to be exploited
Threat Score
36.3 / 100
Data Sources
NVD
EPSS
GitHub