Записи asp-dev
9 опубликованных записей вендора asp-dev.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2005-4165Эксплойта нет | Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) fasp-dev · asp resources forum | Высокая7,5 | — | 1,5 % | 11 дек. 2005 г. |
30Наблюдать | CVE-2012-4061Эксплойта нет | Multiple SQL injection vulnerabilities in ASP-DEv XM Diary allow remote attackers to execute arbitrary SQL commands via the (1) id parameterasp-dev · xm diary · CWE-89 | Высокая7,5 | — | 1,2 % | 25 июл. 2012 г. |
30Наблюдать | CVE-2012-4060Proof of concept | Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameteasp-dev · xm forums · CWE-89 | Высокая7,5 | — | 1,1 % | 25 июл. 2012 г. |
30Наблюдать | CVE-2008-5924Эксплойта нет | SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the asp-dev · xm events diary · CWE-89 | Высокая7,5 | — | 1,0 % | 21 янв. 2009 г. |
30Наблюдать | CVE-2008-5926Proof of concept | Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commanasp-dev · internal e-mail system · CWE-89 | Высокая7,5 | — | 1,0 % | 21 янв. 2009 г. |
30Наблюдать | CVE-2008-5923Proof of concept | SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat paraasp-dev · xm events diary · CWE-89 | Высокая7,5 | — | 1,0 % | 21 янв. 2009 г. |
20Наблюдать | CVE-2008-5925Эксплойта нет | ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to dasp-dev · xm events diary · CWE-264 | Средняя5,0 | — | 1,2 % | 21 янв. 2009 г. |
18Наблюдать | CVE-2005-1008Proof of concept | Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTMasp-dev · xm forum | Средняя4,3 | — | 2,7 % | 2 мая 2005 г. |
17Наблюдать | CVE-2005-4256Proof of concept | Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTMLasp-dev · xm forum | Средняя4,3 | — | 1,5 % | 15 дек. 2005 г. |
- CVE-2005-416530Наблюдать
Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) f
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %asp-dev · asp resources forum11 дек. 2005 г.
- CVE-2012-406130Наблюдать
Multiple SQL injection vulnerabilities in ASP-DEv XM Diary allow remote attackers to execute arbitrary SQL commands via the (1) id parameter
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %asp-dev · xm diary25 июл. 2012 г.
- CVE-2012-406030Наблюдать
Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id paramete
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %asp-dev · xm forums25 июл. 2012 г.
- CVE-2008-592430Наблюдать
SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %asp-dev · xm events diary21 янв. 2009 г.
- CVE-2008-592630Наблюдать
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %asp-dev · internal e-mail system21 янв. 2009 г.
- CVE-2008-592330Наблюдать
SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat para
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %asp-dev · xm events diary21 янв. 2009 г.
- CVE-2008-592520Наблюдать
ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to d
СредняяCVSS 5,0Эксплойта нетEPSS 1 %asp-dev · xm events diary21 янв. 2009 г.
- CVE-2005-100818Наблюдать
Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Proof of conceptEPSS 3 %asp-dev · xm forum2 мая 2005 г.
- CVE-2005-425617Наблюдать
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 2 %asp-dev · xm forum15 дек. 2005 г.