Skip to main content

Vendor archive

iisworks CVEs

Beta · best-effort

6 CVEs tagged to vendor iisworks1 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2006-6350

Published Dec 7, 2006

listpics 5 stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for listpics.mdb.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6210

Published Dec 1, 2006

SQL injection vulnerability in listpics.asp in ASP ListPics 5.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2989

Published Jun 13, 2006

Cross-site scripting (XSS) vulnerability in listpics.asp in ASP ListPics 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the info parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4658

Published Dec 31, 2005

Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vector…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4047

Published Dec 7, 2005

Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3596

Published Nov 16, 2005

SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1