Loading
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).
Use Ipswitch vendor hub and Whatsup product page to widen CVE-2005-1250 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2006-2531 and CVE-2006-0911 for nearby disclosures in the same product family.