Vulnerabilities
Vulnerable Software
Aspapps:  >> Aspportal  >> _nil_  Security Vulnerabilities
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter to classifieds.asp and the (2) ID parameter to Events.asp.
CVSS Score
7.5
EPSS Score
0.002
Published
2008-12-16
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for xportal.mdb.
CVSS Score
5.0
EPSS Score
0.018
Published
2008-12-15


Contact Us

Shodan ® - All rights reserved