Записи aspapps
7 опубликованных записей вендора aspapps.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2008-5605Proof of concept | Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter taspapps · aspportal · CWE-89 | Высокая7,5 | — | 2,1 % | 16 дек. 2008 г. |
30Наблюдать | CVE-2008-5595Proof of concept | SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.aspapps · asp autodealer · CWE-89 | Высокая7,5 | — | 1,2 % | 16 дек. 2008 г. |
30Наблюдать | CVE-2008-5950Proof of concept | SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via aspapps · template creature · CWE-89 | Высокая7,5 | — | 1,0 % | 23 янв. 2009 г. |
22Наблюдать | CVE-2008-5562Proof of concept | ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the daaspapps · aspportal · CWE-264 | Средняя5,0 | — | 5,2 % | 15 дек. 2008 г. |
21Наблюдать | CVE-2008-5608Proof of concept | ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download taspapps · asp autodealer · CWE-264 | Средняя5,0 | — | 2,9 % | 16 дек. 2008 г. |
21Наблюдать | CVE-2008-5603Proof of concept | ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download thaspapps · aspticker · CWE-264 | Средняя5,0 | — | 2,6 % | 16 дек. 2008 г. |
21Наблюдать | CVE-2008-5951Proof of concept | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to dowaspapps · template creature · CWE-264 | Средняя5,0 | — | 2,2 % | 23 янв. 2009 г. |
- CVE-2008-560531Наблюдать
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter t
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %aspapps · aspportal16 дек. 2008 г.
- CVE-2008-559530Наблюдать
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %aspapps · asp autodealer16 дек. 2008 г.
- CVE-2008-595030Наблюдать
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %aspapps · template creature23 янв. 2009 г.
- CVE-2008-556222Наблюдать
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the da
СредняяCVSS 5,0Proof of conceptEPSS 5 %aspapps · aspportal15 дек. 2008 г.
- CVE-2008-560821Наблюдать
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t
СредняяCVSS 5,0Proof of conceptEPSS 3 %aspapps · asp autodealer16 дек. 2008 г.
- CVE-2008-560321Наблюдать
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th
СредняяCVSS 5,0Proof of conceptEPSS 3 %aspapps · aspticker16 дек. 2008 г.
- CVE-2008-595121Наблюдать
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow
СредняяCVSS 5,0Proof of conceptEPSS 2 %aspapps · template creature23 янв. 2009 г.