Back
CVE-2004-1553
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CWE-89
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| fullrevolution | aspwebalbum | 3.2 |
GitHub Security Advisory GHSA-rfmv-7688-qrqx
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL...
References (22)
- http://marc.info/?l=bugtraq&m=109604910025090&w=2
- http://osvdb.org/47913
- http://osvdb.org/47914
- http://secunia.com/advisories/31649 Vendor Advisory
- http://www.securityfocus.com/bid/11246 Exploit
- http://www.securityfocus.com/bid/30996 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17507
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44876
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44877
- https://www.exploit-db.com/exploits/6357
- https://www.exploit-db.com/exploits/6420
- http://marc.info/?l=bugtraq&m=109604910025090&w=2
- http://osvdb.org/47913
- http://osvdb.org/47914
- http://secunia.com/advisories/31649 Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.38%
Top 18% most likely to be exploited
Threat Score
30.7 / 100
Data Sources
NVD
EPSS
GitHub