SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Estate_agent_manager | Iexpress | 1.3 (including) | 1.3 (including) |