vendor:
ASPRunner
by:
Unknown
7.5
CVSS
HIGH
SQL Injection, Cross-Site Scripting, Information Disclosure, Unauthorized Access
Unknown
CWE
Product Name: ASPRunner
Affected Version From: 2.4
Affected Version To: 2.4
Patch Exists: NO
Related CWE: Unknown
CPE: a:xlinesoft:asprunner:2.4
Platforms Tested: Unknown
Unknown
ASPRunner Multiple Vulnerabilities
ASPRunner versions 2.4 and prior are affected by multiple vulnerabilities including SQL injection, cross-site scripting, information disclosure, and unauthorized access to database files. An attacker can exploit these issues by sending a crafted HTTP request to the affected server.
Mitigation:
Upgrade to a version of ASPRunner that is not affected by these vulnerabilities. Additionally, input validation should be implemented to prevent SQL injection and cross-site scripting attacks.