This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Humayun Shabbir Bhutta First view 2009-04-17
Product Asp Product Catalog Last view 2009-07-24
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:humayun_shabbir_bhutta:asp_product_catalog:1.0:*:*:*:*:*:*:* 3

Related : CVE

  Date Alert Description
7.5 2009-07-24 CVE-2008-6875

SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.

5 2009-04-17 CVE-2009-1322

ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.

4.3 2009-04-17 CVE-2009-1321

Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

CWE : Common Weakness Enumeration

%idName
33% (1) CWE-264 Permissions, Privileges, and Access Controls
33% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...
33% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Open Source Vulnerability Database (OSVDB)

id Description
53786 ASP Product Catalog database/aspProductCatalog.mdb Direct Request User Creden...
53785 ASP Product Catalog search.asp keywords Parameter XSS
51976 ASP Product Catalog default.asp cid Parameter SQL Injection