Virtual Programming's vulnerability footprint centers on a narrowly scoped product line focused on server-side web application platforms, such as VP-ASP, that occupy a specialized niche in the deployment landscape. The vendor's disclosures frequently acquire public exploit code, which reflects the accessibility and interest surrounding web-facing application servers as targets for post-exploitation and lateral movement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virtual Programming over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0560HIGH SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter. | Aug 18, 2003 | 10.0 | 42 | NO | YES |
CVE-2004-2413HIGH SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters i | Dec 31, 2004 | 7.5 | 34 | NO | YES |
CVE-2007-0224HIGH SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parame | Jan 13, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-2263HIGH SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | May 9, 2006 | 7.5 | 28 | NO | YES |
CVE-2007-0225MEDIUM Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg pa | Jan 13, 2007 | 6.8 | 26 | NO | YES |
CVE-2004-2411MEDIUM The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site script | Dec 31, 2004 | 4.3 | 26 | NO | YES |
CVE-2005-3685MEDIUM Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter. | Nov 19, 2005 | 4.3 | 21 | NO | YES |
CVE-2004-2412HIGH Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via the catalogid parameter in (1) shoprevie | Dec 31, 2004 | 7.5 | 19 | NO | NO |
CVE-2002-1919HIGH SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password | Dec 31, 2002 | 7.5 | 19 | NO | NO |
CVE-2004-2164MEDIUM shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connect | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtual Programming.
Media articles that mention a CVE ID that affects a product developed by Virtual Programming — matched by CVE ID, not by vendor name.