Vulnerability Description
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Biztalk Server | 2000 |
References
- http://marc.info/?l=bugtraq&m=105216839231951&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-01
- http://marc.info/?l=bugtraq&m=105216839231951&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-01
FAQ
What is CVE-2003-0118?
CVE-2003-0118 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a reque...
How severe is CVE-2003-0118?
CVE-2003-0118 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0118?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Biztalk Server.