VYPR
Vendor

Asp CMS

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2019-25765HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.01

    ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword…

  • CVE-2008-6353Mar 2, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.

  • CVE-2007-5260Oct 6, 2007
    risk 0.00cvss epss 0.01

    ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request for mdb-database/ASP-CMS_v100.mdb.