CVE-2008-6152

Publication date

2009-02-16 17:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: this was originally reported for Lawyer Portal, which does not have a deptdisplay.asp file.