Product
An unauthenticated SQL injection vulnerability in the ASP-CMS commentList.asp endpoint allows remote attackers to bypass keyword filters and extract sensitive database contents via the id parameter.