5
CVSSv2

CVE-2004-2060

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote malicious users to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

Vulnerable Product Search on Vulmon Subscribe to Product

xlinesoft asprunner 2.2

xlinesoft asprunner 2.3

xlinesoft asprunner 2.4

xlinesoft asprunner 1.0

xlinesoft asprunner 2.0

xlinesoft asprunner 2.1

Exploits

source: wwwsecurityfocuscom/bid/10799/info ASPRunner is reported prone to multiple vulnerabilities The reported issues include SQL injection, cross-site scripting, information disclosure and unauthorized access to database files ASPRunner versions 24 and prior are affect by these issues wwwexamplecom/db/[DB-FILE-NAME] ...