PT-2002-2452 · Aspjar · Aspjar Guestbook
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1730
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ASPjar Guestbook version 1.00
Description
The issue allows remote attackers to delete arbitrary messages by accessing the "delete.asp" administrative script with certain cookie values set to
true.Recommendations
For ASPjar Guestbook version 1.00, consider restricting access to the delete.asp administrative script until a patch is available. As a temporary workaround, avoid setting certain cookie values to
true to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aspjar Guestbook