CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Humayun Shabbir Bhutta 1Asp Product Catalog Apr 23, 2026 Jul 24, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220. |
1Humayun Shabbir Bhutta 1Asp Product Catalog Apr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database...Show more |
1Humayun Shabbir Bhutta 1Asp Product Catalog Apr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. |