PT-2004-3059 · Vp Asp · Vp-Asp
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2164
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
VP-ASP version 5.0
Description
The issue concerns a denial of service caused by connection consumption. This occurs because the
shoprestoreorder.asp page in VP-ASP does not properly close the database connection when a user restores a previous order, allowing remote attackers to exploit this behavior.Recommendations
For VP-ASP version 5.0, ensure that the database connection is properly closed after a user restores a previous order to prevent connection consumption. Consider modifying the
shoprestoreorder.asp page to include proper connection closure.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vp-Asp