Vulnerabilities > CVE-2004-1400 - Unspecified vulnerability in Active Server Corner ASP Calendar 1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Active Server Corner ASP Calendar 1.0 Administrative Access Vulnerability. CVE-2004-1400. Webapps exploit for asp platform |
id | EDB-ID:24838 |
last seen | 2016-02-03 |
modified | 2004-12-14 |
published | 2004-12-14 |
reporter | ali reza AcTiOnSpIdEr |
source | https://www.exploit-db.com/download/24838/ |
title | Active Server Corner ASP Calendar 1.0 Administrative Access Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | OCEAN12ASPCALENDAR.NASL |
description | The remote host is running Ocean12 ASP Calendar, a web-based application written in ASP. There is a flaw in the remote software which may allow anyone execute administrative commands on the remote host by requesting the page /admin/main.asp. An attacker may exploit this flaw to deface the remote site without any credentials. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15974 |
published | 2004-12-15 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15974 |
title | Ocean12 ASP Calendar Administrative Access |
code |
|