Aspapps develops a narrow line of web-based business applications including auto-dealer management, portal, and ticketing software, where the recurring vulnerability signal centers on SQL injection across input-handling code. The vendor's disclosures frequently acquire public exploit tooling, reflecting the accessibility of these web-facing applications to external testing and the maturity of SQL-injection attack chains. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aspapps over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5950HIGH SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter. | Jan 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5605HIGH Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter to classifieds.asp and the (2) ID paramet | Dec 16, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5595HIGH SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Dec 16, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5562MEDIUM ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for xpo | Dec 15, 2008 | 5.0 | 24 | NO | YES |
CVE-2008-5951MEDIUM ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct req | Jan 23, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-5608MEDIUM ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request fo | Dec 16, 2008 | 5.0 | 23 | NO | YES |
CVE-2008-5603MEDIUM ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for | Dec 16, 2008 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aspapps.
Media articles that mention a CVE ID that affects a product developed by Aspapps — matched by CVE ID, not by vendor name.