Back

CVE-2004-1553

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
fullrevolution aspwebalbum 3.2

GitHub Security Advisory GHSA-rfmv-7688-qrqx

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.38%

Top 18% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub