SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/9015
http://www.securityfocus.com/bid/4676