aspapps records
7 published records for vendor aspapps.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2008-5605Proof of concept | Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter taspapps · aspportal · CWE-89 | High7.5 | — | 2.1% | Dec 16, 2008 |
30Monitor | CVE-2008-5595Proof of concept | SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.aspapps · asp autodealer · CWE-89 | High7.5 | — | 1.2% | Dec 16, 2008 |
30Monitor | CVE-2008-5950Proof of concept | SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via aspapps · template creature · CWE-89 | High7.5 | — | 1.0% | Jan 23, 2009 |
22Monitor | CVE-2008-5562Proof of concept | ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the daaspapps · aspportal · CWE-264 | Medium5.0 | — | 5.2% | Dec 15, 2008 |
21Monitor | CVE-2008-5608Proof of concept | ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download taspapps · asp autodealer · CWE-264 | Medium5.0 | — | 2.9% | Dec 16, 2008 |
21Monitor | CVE-2008-5603Proof of concept | ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download thaspapps · aspticker · CWE-264 | Medium5.0 | — | 2.6% | Dec 16, 2008 |
21Monitor | CVE-2008-5951Proof of concept | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to dowaspapps · template creature · CWE-264 | Medium5.0 | — | 2.2% | Jan 23, 2009 |
- CVE-2008-560531Monitor
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter t
HighCVSS 7.5Proof of conceptEPSS 2%aspapps · aspportalDec 16, 2008
- CVE-2008-559530Monitor
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.
HighCVSS 7.5Proof of conceptEPSS 1%aspapps · asp autodealerDec 16, 2008
- CVE-2008-595030Monitor
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%aspapps · template creatureJan 23, 2009
- CVE-2008-556222Monitor
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the da
MediumCVSS 5.0Proof of conceptEPSS 5%aspapps · aspportalDec 15, 2008
- CVE-2008-560821Monitor
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t
MediumCVSS 5.0Proof of conceptEPSS 3%aspapps · asp autodealerDec 16, 2008
- CVE-2008-560321Monitor
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th
MediumCVSS 5.0Proof of conceptEPSS 3%aspapps · asptickerDec 16, 2008
- CVE-2008-595121Monitor
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow
MediumCVSS 5.0Proof of conceptEPSS 2%aspapps · template creatureJan 23, 2009