Vulnerabilities > CVE-2002-0607 - SQL Injection vulnerability in Snitz Forums 2000 Members.ASP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
snitz-communications
exploit available

Summary

members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.

Exploit-Db

descriptionSnitz Forums 2000 3.x Members.ASP SQL Injection Vulnerability. CVE-2002-0607. Webapps exploit for asp platform
idEDB-ID:21400
last seen2016-02-02
modified2002-04-19
published2002-04-19
reporteracemi
sourcehttps://www.exploit-db.com/download/21400/
titleSnitz Forums 2000 3.x Members.ASP SQL Injection Vulnerability