SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Estate_agent_manager | Iexpress | 1.3 (including) | 1.3 (including) |