WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xpede | Workforceroi | 4.1 (including) | 4.1 (including) |