RULE(RULE ID:337973)

Rule General Information
Release Date: 2024-05-06
Rule Name: Aspcms commentList.asp SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: ASPCMS website building system is an open source CMS system based on ASP.Net, can be competent for a variety of enterprise website needs, and support template customization, support extension plug-ins, etc., can complete the enterprise website in a short time. AspCMS commentList.asp has a SQL injection vulnerability. This vulnerability is caused by the value of the id parameter is not effectively filtered, and a malicious attacker can use this vulnerability for SQL injection.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.