5
CVSSv2

CVE-2004-2059

Published: 31/12/2004 Updated: 19/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 520
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote malicious users to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

xlinesoft asprunner 2.0

xlinesoft asprunner 2.1

xlinesoft asprunner 2.2

xlinesoft asprunner 2.3

xlinesoft asprunner 2.4

xlinesoft asprunner 1.0

Exploits

source: wwwsecurityfocuscom/bid/10799/info ASPRunner is reported prone to multiple vulnerabilities The reported issues include SQL injection, cross-site scripting, information disclosure and unauthorized access to database files ASPRunner versions 24 and prior are affect by these issues wwwexamplecom/[TABLE-NAME]_searchasp ...
source: wwwsecurityfocuscom/bid/10799/info ASPRunner is reported prone to multiple vulnerabilities The reported issues include SQL injection, cross-site scripting, information disclosure and unauthorized access to database files ASPRunner versions 24 and prior are affect by these issues wwwexamplecom/[TABLE-NAME]_editasp ...
source: wwwsecurityfocuscom/bid/10799/info ASPRunner is reported prone to multiple vulnerabilities The reported issues include SQL injection, cross-site scripting, information disclosure and unauthorized access to database files ASPRunner versions 24 and prior are affect by these issues wwwexamplecom/exportasp?SQL=%22%3E ...
source: wwwsecurityfocuscom/bid/10799/info ASPRunner is reported prone to multiple vulnerabilities The reported issues include SQL injection, cross-site scripting, information disclosure and unauthorized access to database files ASPRunner versions 24 and prior are affect by these issues wwwexamplecom/[TABLE-NAME]_listasp ...