Synopsis
The remote host has a ASP script that is affected by a SQL injection vulnerability.
Description
The remote host is using the VP-ASP, a shopping cart program written in ASP. The remote version of this software contains three SQL injection vulnerabilities in the files shopaddtocart.asp, shopaddtocartnodb.asp and shopproductselect.asp. An attacker may exploit these flaws to execute arbitrary SQL statements against the remote database.
Solution
See http://www.nessus.org/u?47e969b3
Plugin Details
File Name: vp-asp_sql_injection2.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Vulnerability Publication Date: 7/18/2005