Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.Referenceshttps://www.exploit-db.com/exploits/7283http://secunia.com/advisories/32921http://www.vupen.com/english/advisories/2008/3296https://exchange.xforce.ibmcloud.com/vulnerabilities/46909