CVE-2012-4976: Layton Technology Helpbox

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is not properly handled during construction of an error page.

Affected products

Published 2012-12-12. Last modified 2026-06-16.