Vulnerabilities > CVE-2003-0215 - Unspecified vulnerability in Battleaxe Software Bttlxeforum
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Battleaxe Software BTTLXE Forum Login.ASP SQL Injection Vulnerability. CVE-2003-0215. Webapps exploit for asp platform |
id | EDB-ID:22529 |
last seen | 2016-02-02 |
modified | 2003-04-23 |
published | 2003-04-23 |
reporter | Du|L |
source | https://www.exploit-db.com/download/22529/ |
title | Battleaxe Software BTTLXE Forum Login.ASP SQL Injection Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | BTTLXE_SQL_INJECTION.NASL |
description | The remote host is running bttlxeForum, a set of CGIs designed to run a forum-based web server on Windows. There is a SQL injection bug in the remote server that allowed Nessus to log in as |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11548 |
published | 2003-04-24 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11548 |
title | bttlxeForum login.asp Multiple Field SQL Injection |
code |
|
References
- http://marc.info/?l=bugtraq&m=105120052725940&w=2
- http://marc.info/?l=bugtraq&m=105120052725940&w=2
- http://securitytracker.com/id?1006632
- http://securitytracker.com/id?1006632
- http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&select=1812
- http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&select=1812