Skip to main content

Vendor/product archive

xlinesoft / asprunner CVEs

Beta · best-effort

4 CVEs tagged to xlinesoft / asprunner0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2004-2057

Published Dec 31, 2004

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2058

Published Dec 31, 2004

ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2059

Published Dec 31, 2004

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2060

Published Dec 31, 2004

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1