7.5
CVSSv2

CVE-2003-0377

Published: 16/06/2003 Updated: 13/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote malicious users to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.

Vulnerable Product Search on Vulmon Subscribe to Product

iisprotect iisprotect

Exploits

source: wwwsecurityfocuscom/bid/7675/info The IISProtect web administration interface does not properly sanitize user input This could allow for SQL injection attacks on a Microsoft IIS server running IISProtect Successful exploitation could result in a compromise of the IISProtect server, attacks on the database or other consequences ...