Vulnerabilities > CVE-2003-0509 - Unspecified vulnerability in Cyberstrong Eshop
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description CyberStrong eShop 4.2 10expand.ASP SQL Injection Vulnerability. CVE-2003-0509. Webapps exploit for asp platform id EDB-ID:25923 last seen 2016-02-03 modified 2005-06-30 published 2005-06-30 reporter [email protected] source https://www.exploit-db.com/download/25923/ title CyberStrong eShop 4.2 10expand.ASP SQL Injection Vulnerability description CyberStrong EShop 4.2 20review.ASP SQL Injection Vulnerability. CVE-2003-0509. Webapps exploit for asp platform id EDB-ID:25922 last seen 2016-02-03 modified 2005-06-30 published 2005-06-30 reporter [email protected] source https://www.exploit-db.com/download/25922/ title CyberStrong EShop 4.2 20review.ASP SQL Injection Vulnerability
Nessus
NASL family | CGI abuses |
NASL id | CYBERSTRONG_ESHOP_SQL.NASL |
description | The remote host is running Cyberstrong eShop, a shopping cart written in ASP. The remote version of this software contains several input validation flaws leading to SQL injection vulnerabilities. An attacker may exploit these flaws to affect database queries, possibly resulting in disclosure of sensitive information (for example, the admin |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19391 |
published | 2005-08-07 |
reporter | Copyright (C) 2005-2018 Josh Zlatin-Amishav |
source | https://www.tenable.com/plugins/nessus/19391 |
title | Cyberstrong eShop Multiple Script ProductCode Parameter SQL Injection |
code |
|
References
- http://marc.info/?l=bugtraq&m=105709450711395&w=2
- http://marc.info/?l=bugtraq&m=105709450711395&w=2
- http://secunia.com/advisories/9165
- http://secunia.com/advisories/9165
- http://securitytracker.com/id?1007092
- http://securitytracker.com/id?1007092
- http://www.osvdb.org/10098
- http://www.osvdb.org/10098
- http://www.osvdb.org/10099
- http://www.osvdb.org/10099
- http://www.osvdb.org/10100
- http://www.osvdb.org/10100
- http://www.securityfocus.com/bid/14101
- http://www.securityfocus.com/bid/14101
- http://www.securityfocus.com/bid/14103
- http://www.securityfocus.com/bid/14103
- http://www.securityfocus.com/bid/14112
- http://www.securityfocus.com/bid/14112
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12485
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12485