Vulnerabilities > CVE-2002-1499 - Unspecified vulnerability in Factosystem Weblog 0.9B/1.0Beta/1.1Beta

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
factosystem
exploit available

Summary

Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

Exploit-Db

descriptionFactoSystem Weblog 0.9/1.0/1.1 Multiple SQL Injection Vulnerabilities. CVE-2002-1499. Webapps exploit for asp platform
idEDB-ID:21766
last seen2016-02-02
modified2002-08-31
published2002-08-31
reporterMatthew Murphy
sourcehttps://www.exploit-db.com/download/21766/
titleFactoSystem Weblog 0.9/1.0/1.1 - Multiple SQL Injection Vulnerabilities