Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.7
CVE-2019-25765
- EPSS 0.59%
- Veröffentlicht 13.08.2026 17:21:38
- Zuletzt bearbeitet 14.08.2026 19:17:12
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass t...
7.5
CVE-2008-6353
- EPSS 0.97%
- Veröffentlicht 02.03.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:02:04
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.
- EPSS 1.06%
- Veröffentlicht 06.10.2007 17:17:00
- Zuletzt bearbeitet 16.06.2026 22:45:45
ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request for mdb-database/ASP-CMS_v100.mdb.
1