Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-1553

Опубликовано: 31 дек. 2004
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fullrevolution:aspwebalbum:3.2:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.04063
Низкий

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
почти 4 года назад

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

EPSS

Процентиль: 88%
0.04063
Низкий

7.5 High

CVSS2

Дефекты

CWE-89