Vulnerabilities > Iisworks

DATE CVE VULNERABILITY TITLE RISK
2006-12-07 CVE-2006-6350 Remote Security vulnerability in Iisworks Listpics 5.0
listpics 5 stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for listpics.mdb.
network
low complexity
iisworks
critical
10.0
2006-12-01 CVE-2006-6210 SQL Injection vulnerability in Iisworks ASP Listpics 5.0
SQL injection vulnerability in listpics.asp in ASP ListPics 5.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
network
low complexity
iisworks
7.5
2006-06-13 CVE-2006-2989 Cross-Site Scripting vulnerability in ListPics
Cross-site scripting (XSS) vulnerability in listpics.asp in ASP ListPics 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the info parameter.
network
iisworks
4.3
2005-12-31 CVE-2005-4658 Cross-Site Scripting vulnerability in Iisworks Aspknowledgebase
Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.
network
iisworks CWE-79
6.8
2005-12-07 CVE-2005-4047 Cross-Site Scripting vulnerability in Iisworks Aspknowledgebase 2.0
Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.
network
iisworks
4.3
2005-11-16 CVE-2005-3596 Unspecified vulnerability in Iisworks Aspknowledgebase
SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp.
network
low complexity
iisworks
7.5