VulnerabilityModified
CVE-2002-0581
WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.
HIGH 7.5EPSS 1.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- workforceroi/xpede
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0273.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/8903.phpVendor Advisory
- http://www.securityfocus.com/bid/4555Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0273.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/8903.phpVendor Advisory
- http://www.securityfocus.com/bid/4555Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.