fipsasp records
12 published records for vendor fipsasp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-264 Permissions, Privileges, and Access Controls2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2006-6117Proof of concept | SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the wfipsasp · fipsgallery | High7.5 | — | 1.2% | Nov 26, 2006 |
30Monitor | CVE-2006-6115Proof of concept | SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid pafipsasp · fipscms | High7.5 | — | 1.2% | Nov 26, 2006 |
30Monitor | CVE-2006-6116Proof of concept | SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kfipsasp · fipsforum | High7.5 | — | 1.2% | Nov 26, 2006 |
30Monitor | CVE-2006-6243Proof of concept | Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or fipsasp · fipsshop | High7.5 | — | 1.2% | Dec 4, 2006 |
30Monitor | CVE-2008-3417Proof of concept | SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands viafipsasp · fipscms light · CWE-89 | High7.5 | — | 1.0% | Jul 31, 2008 |
30Monitor | CVE-2007-2561Proof of concept | SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a dfipsasp · fipscms | High7.5 | — | 1.0% | May 9, 2007 |
30Monitor | CVE-2008-2124Proof of concept | SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parfipsasp · fipscms · CWE-89 | High7.5 | — | 1.0% | May 9, 2008 |
30Monitor | CVE-2008-3722Proof of concept | SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter.fipsasp · fipscms · CWE-89 | High7.5 | — | 1.0% | Aug 20, 2008 |
28Monitor | CVE-2006-3022No exploit | Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script ofipsasp · fipsgallery | Medium6.8 | — | 2.0% | Jun 15, 2006 |
22Monitor | CVE-2009-2022Proof of concept | fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloafipsasp · fipscms light · CWE-264 | Medium5.0 | — | 5.2% | Jun 9, 2009 |
21Monitor | CVE-2010-0765Proof of concept | fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a fipsasp · fipsforum · CWE-264 | Medium5.0 | — | 2.4% | Mar 2, 2010 |
17Monitor | CVE-2006-3031No exploit | Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web sfipsasp · fipscms | Medium4.3 | — | 1.2% | Jun 15, 2006 |
- CVE-2006-611730Monitor
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the w
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipsgalleryNov 26, 2006
- CVE-2006-611530Monitor
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid pa
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipscmsNov 26, 2006
- CVE-2006-611630Monitor
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the k
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipsforumNov 26, 2006
- CVE-2006-624330Monitor
Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipsshopDec 4, 2006
- CVE-2008-341730Monitor
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipscms lightJul 31, 2008
- CVE-2007-256130Monitor
SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a d
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipscmsMay 9, 2007
- CVE-2008-212430Monitor
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg par
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipscmsMay 9, 2008
- CVE-2008-372230Monitor
SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
HighCVSS 7.5Proof of conceptEPSS 1%fipsasp · fipscmsAug 20, 2008
- CVE-2006-302228Monitor
Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script o
MediumCVSS 6.8No exploitEPSS 2%fipsasp · fipsgalleryJun 15, 2006
- CVE-2009-202222Monitor
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa
MediumCVSS 5.0Proof of conceptEPSS 5%fipsasp · fipscms lightJun 9, 2009
- CVE-2010-076521Monitor
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a
MediumCVSS 5.0Proof of conceptEPSS 2%fipsasp · fipsforumMar 2, 2010
- CVE-2006-303117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web s
MediumCVSS 4.3No exploitEPSS 1%fipsasp · fipscmsJun 15, 2006