Back
CVE-2002-1919
SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| virtual_programming | vp-asp | 4.0 |
GitHub Security Advisory GHSA-r9wh-7cm5-9f5j
SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute...
References (6)
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0233.html
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0061.html
- http://www.securityfocus.com/bid/4861
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0233.html
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0061.html
- http://www.securityfocus.com/bid/4861
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.52%
Top 28% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub