SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Maxwebportal | Maxwebportal | 1.35 (including) | 1.35 (including) |
| Maxwebportal | Maxwebportal | 1.36 (including) | 1.36 (including) |
| Maxwebportal | Maxwebportal | 2.0 (including) | 2.0 (including) |
| Maxwebportal | Maxwebportal | 2005-04-18 (including) | 2005-04-18 (including) |