Vulnerability Description
SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Expinion.Net | Member Management System | 2.1 |
References
- http://marc.info/?l=bugtraq&m=107999697625786&w=2
- http://secunia.com/advisories/11179ExploitPatchVendor Advisory
- http://securitytracker.com/id?1009508ExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/9931PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15551
- http://marc.info/?l=bugtraq&m=107999697625786&w=2
- http://secunia.com/advisories/11179ExploitPatchVendor Advisory
- http://securitytracker.com/id?1009508ExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/9931PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15551
FAQ
What is CVE-2004-1843?
CVE-2004-1843 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.
How severe is CVE-2004-1843?
CVE-2004-1843 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1843?
Check the references section above for vendor advisories and patch information. Affected products include: Expinion.Net Member Management System.