CVE-2008-5571
Summary
| CVE | CVE-2008-5571 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-15 18:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dotnetindex | Professional Download Assistant | 0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityReason - Professional Download Assistant 0.1 (Auth Bypass) SQL Injection Vuln | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Professional Download Assistant 0.1 (Auth Bypass) SQL Injection Vuln | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| osvdb.org/50548 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| dotnetindex Professional Download Assistant SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Professional Download Assistant SQL Injections and Database Disclosure - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.