Nuclei TemplateThird-party advisory
https://github.com/projectdiscovery/nuclei-templates/issues/7968 CVE-2019-25765
HIGH
ASP-CMS SQL Injection via commentList.asp id Parameter
Record summary
CVE-2019-25765 has a selected CVSS score of 8.7 (high).
Description
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 13, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version range not supplied | affected |
References
5Researcher DisclosureTechnical descriptionexploit
https://web.archive.org/web/20201001011935/https://www.safeinfo.me/2019/07/22/aspcms-lou-dong-ji-he.html Archived SourceForge Pageproduct
https://web.archive.org/web/20220425041152/https://asp-cms.sourceforge.net DayDayPoC AdvisoryThird-party advisory
https://www.ddpoc.com/DVB-2021-821.html vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/asp-cms-sql-injection-via-commentlist-asp-id-parameter