ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16802
http://www.securityfocus.com/bid/10799
http://securitytracker.com/id?1010777