CVE-2008-5605 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter to classifieds.asp and the (2) ID parameter to Events.asp.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.08% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-12-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| aspapps | aspportal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ASP Portal - Multiple SQL Injections | 2008-12-05 |
References
- http://securityreason.com/securityalert/4763
- http://www.securityfocus.com/bid/32662
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47127
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47268
- https://www.exploit-db.com/exploits/7357
- http://securityreason.com/securityalert/4763
- http://www.securityfocus.com/bid/32662
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47127
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47268
- https://www.exploit-db.com/exploits/7357
→ the Explorer · watch your stack · NVD