{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/asp-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2019-25765"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ASP-CMS"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["ASP-CMS"],"content_html":"\u003cp\u003eASP-CMS contains a critical SQL injection vulnerability in the commentList.asp endpoint, identified as CVE-2019-25765. This flaw allows unauthenticated remote attackers to execute arbitrary SQL queries by manipulating the id parameter within GET requests. The vulnerability is significant because attackers can circumvent existing application-level keyword blocklists - used to prevent common SQL injection patterns - by interleaving specific strings, such as 'master', into prohibited SQL keywords. This obfuscation technique enables the successful extraction of sensitive database contents. The Shadowserver Foundation first observed exploitation of this vulnerability on October 18, 2023. Given the ease of exploitation via simple HTTP GET requests and the potential for unauthorized data exfiltration, organizations utilizing ASP-CMS must prioritize remediation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify sites running ASP-CMS and target the commentList.asp script.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting the 'id' parameter.\u003c/li\u003e\n\u003cli\u003eAttacker uses SQL injection techniques, embedding obfuscated keywords (e.g., 'ma' + 'ster') to bypass internal blocklists.\u003c/li\u003e\n\u003cli\u003eThe vulnerable commentList.asp endpoint processes the unsanitized 'id' parameter input.\u003c/li\u003e\n\u003cli\u003eThe underlying database executes the injected SQL command.\u003c/li\u003e\n\u003cli\u003eAttacker observes application responses (or error messages) to confirm successful injection.\u003c/li\u003e\n\u003cli\u003eAttacker iterates requests to systematically dump table names, schemas, or sensitive records from the database.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: unauthorized exfiltration of sensitive database data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform arbitrary database queries against an ASP-CMS installation. This can lead to the full compromise of database contents, including user credentials, administrative configurations, and application data. Historically, this has resulted in data exfiltration incidents observed globally since October 2023.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all web servers hosting ASP-CMS for the presence of the vulnerable commentList.asp endpoint.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to web server access logs to detect potential SQL injection attempts targeting the id parameter.\u003c/li\u003e\n\u003cli\u003ePatch or update the ASP-CMS installation to a version that implements proper parameter sanitization and parameterized queries.\u003c/li\u003e\n\u003cli\u003eApply a Web Application Firewall (WAF) rule to block requests where the 'id' parameter contains suspicious SQL patterns, specifically those attempting to bypass blocklists using obfuscation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T18:56:36Z","date_published":"2026-08-13T18:56:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-asp-cms-sql-injection/","summary":"An unauthenticated SQL injection vulnerability in the ASP-CMS commentList.asp endpoint allows remote attackers to bypass keyword filters and extract sensitive database contents via the id parameter.","title":"SQL Injection Vulnerability in ASP-CMS commentList.asp","url":"https://feed.craftedsignal.io/briefs/2026-08-asp-cms-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - ASP-CMS","version":"https://jsonfeed.org/version/1.1"}