CVE Vulnerabilities

CVE-2002-1499

Published: Apr 02, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

Affected Software

Name Vendor Start Version End Version
Factosystem_weblog Factosystem 0.9b 0.9b
Factosystem_weblog Factosystem 1.0_beta 1.0_beta
Factosystem_weblog Factosystem 1.1_beta 1.1_beta

References