7.5
CVSSv2

CVE-2002-0607

Published: 18/06/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

members.asp in Snitz Forums 2000 version 3.3.03 and previous versions allows remote malicious users to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.

Vulnerable Product Search on Vulmon Subscribe to Product

snitz communications snitz forums 2000 3.0

snitz communications snitz forums 2000 3.1

snitz communications snitz forums 2000 3.3.01

snitz communications snitz forums 2000 3.3.03

snitz communications snitz forums 2000 3.3

snitz communications snitz forums 2000 3.3.02

Exploits

source: wwwsecurityfocuscom/bid/4558/info Snitz Forums 2000 is ASP-based web forum software It runs on Microsoft Windows operating systems Snitz is back-ended by a database and supports Microsoft Access 97/2000, SQL Server 65/70/2000 and MySQL It is possible for a remote attacker to inject SQL into queries made by the membersasp sc ...