VYPR

Asp Stats Generator

by Asp Stats Generator

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2006-31840.040.09Jun 23, 2006Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.
CVE-2006-35800.030.01Jul 13, 2006SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.