aspapps kayıtları
aspapps üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2008-5605Kavram kanıtı | Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter taspapps · aspportal · CWE-89 | Yüksek7,5 | — | %2,1 | 16 Ara 2008 |
30İzleyin | CVE-2008-5595Kavram kanıtı | SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.aspapps · asp autodealer · CWE-89 | Yüksek7,5 | — | %1,2 | 16 Ara 2008 |
30İzleyin | CVE-2008-5950Kavram kanıtı | SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via aspapps · template creature · CWE-89 | Yüksek7,5 | — | %1,0 | 23 Oca 2009 |
22İzleyin | CVE-2008-5562Kavram kanıtı | ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the daaspapps · aspportal · CWE-264 | Orta5,0 | — | %5,2 | 15 Ara 2008 |
21İzleyin | CVE-2008-5608Kavram kanıtı | ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download taspapps · asp autodealer · CWE-264 | Orta5,0 | — | %2,9 | 16 Ara 2008 |
21İzleyin | CVE-2008-5603Kavram kanıtı | ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download thaspapps · aspticker · CWE-264 | Orta5,0 | — | %2,6 | 16 Ara 2008 |
21İzleyin | CVE-2008-5951Kavram kanıtı | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to dowaspapps · template creature · CWE-264 | Orta5,0 | — | %2,2 | 23 Oca 2009 |
- CVE-2008-560531İzleyin
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter t
YüksekCVSS 7,5Kavram kanıtıEPSS %2aspapps · aspportal16 Ara 2008
- CVE-2008-559530İzleyin
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspapps · asp autodealer16 Ara 2008
- CVE-2008-595030İzleyin
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspapps · template creature23 Oca 2009
- CVE-2008-556222İzleyin
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the da
OrtaCVSS 5,0Kavram kanıtıEPSS %5aspapps · aspportal15 Ara 2008
- CVE-2008-560821İzleyin
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t
OrtaCVSS 5,0Kavram kanıtıEPSS %3aspapps · asp autodealer16 Ara 2008
- CVE-2008-560321İzleyin
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th
OrtaCVSS 5,0Kavram kanıtıEPSS %3aspapps · aspticker16 Ara 2008
- CVE-2008-595121İzleyin
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow
OrtaCVSS 5,0Kavram kanıtıEPSS %2aspapps · template creature23 Oca 2009