Vulnerability Description
SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snitz Communications | Snitz Forums 2000 | <= 3.3.03 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html
- http://marc.info/?l=bugtraq&m=105277599131134&w=2
- http://osvdb.org/56166
- http://packetstormsecurity.org/0305-exploits/snitz_exec.txtExploit
- http://secunia.com/advisories/35733Vendor Advisory
- http://www.securityfocus.com/bid/35764ExploitPatch
- http://www.securityfocus.com/bid/7549ExploitPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11981
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html
- http://marc.info/?l=bugtraq&m=105277599131134&w=2
- http://osvdb.org/56166
- http://packetstormsecurity.org/0305-exploits/snitz_exec.txtExploit
- http://secunia.com/advisories/35733Vendor Advisory
- http://www.securityfocus.com/bid/35764ExploitPatch
- http://www.securityfocus.com/bid/7549ExploitPatch
FAQ
What is CVE-2003-0286?
CVE-2003-0286 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.
How severe is CVE-2003-0286?
CVE-2003-0286 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0286?
Check the references section above for vendor advisories and patch information. Affected products include: Snitz Communications Snitz Forums 2000.