peter bassill · operator
$ cve CVE-2004-1553 JSON

CVE-2004-1553 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 83)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.38% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
fullrevolutionaspwebalbum

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD