Vulnerabilities > CVE-2004-1401 - Unspecified vulnerability in Asp-Rider
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ASP-Rider Remote SQL Injection Vulnerability. CVE-2004-1401. Webapps exploit for asp platform |
id | EDB-ID:24840 |
last seen | 2016-02-03 |
modified | 2004-12-14 |
published | 2004-12-14 |
reporter | Shervin Khaleghjou |
source | https://www.exploit-db.com/download/24840/ |
title | ASP-Rider Remote SQL Injection Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | ASPRIDER_SQL.NASL |
description | The remote host appears to be running ASP-Rider, a set of ASP scripts designed to maintain a blog. There is a flaw in the remote software that could allow anyone to inject arbitrary SQL commands, which could in turn be used to gain administrative access on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15968 |
published | 2004-12-14 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15968 |
title | ASP-Rider verify.asp username Parameter SQL Injection |
code |
|
References
- http://marc.info/?l=bugtraq&m=110305802005220&w=2
- http://marc.info/?l=bugtraq&m=110305802005220&w=2
- http://secunia.com/advisories/13470/
- http://secunia.com/advisories/13470/
- http://www.securityfocus.com/bid/11933
- http://www.securityfocus.com/bid/11933
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18479
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18479