Description
SQL injection vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the newsid parameter when the sec parameter is 26. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/62358
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38596
Scores
EPSS
0.0100
EPSS Percentile
59.2%
Details
CWE
CWE-89
Status
published
Products (2)
aspcodecms/aspcode_cms
1.5.8
aspcodecms/aspcode_cms
2.0.0
Published
Feb 25, 2010
Tracked Since
Feb 18, 2026