Fipsasp maintains a small portfolio of web-based content management and community platform products including FipsCMS, FipsForum, and FipsGallery that serve niche deployment contexts. The vendor's disclosed vulnerabilities center on SQL injection and input-handling weaknesses characteristic of web applications, and public exploit code has become readily available for this product line. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fipsasp over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2022MEDIUM fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive | Jun 9, 2009 | 5.0 | 35 | NO | YES |
CVE-2008-3722HIGH SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter. NOTE: the provenance of this informati | Aug 20, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3417HIGH SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector tha | Jul 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-2124HIGH SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter. | May 9, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-2561HIGH SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115. | May 9, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-6243HIGH Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter. | Dec 4, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6115HIGH SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter. | Nov 26, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6116HIGH SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter. | Nov 26, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6117HIGH SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter. | Nov 26, 2006 | 7.5 | 28 | NO | YES |
CVE-2010-0765MEDIUM fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for _datab | Mar 2, 2010 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fipsasp.
Media articles that mention a CVE ID that affects a product developed by Fipsasp — matched by CVE ID, not by vendor name.