Vulnerabilities
Vulnerable Software
Classapps:  >> Selectsurvey.net  Security Vulnerabilities
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in sequential order beginning from 1.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-01-28
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.
CVSS Score
9.8
EPSS Score
0.034
Published
2022-01-28
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via the SurveyID parameter to survey/ReviewReadOnlySurvey.aspx or (2) remote authenticated users to execute arbitrary SQL commands via the SurveyID parameter to survey/UploadImagePopupToDb.aspx.
CVSS Score
6.5
EPSS Score
0.007
Published
2014-11-06


Contact Us

Shodan ® - All rights reserved