CVE Vulnerabilities

CVE-2003-0118

Published: May 12, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.

Affected Software

NameVendorStart VersionEnd Version
Biztalk_serverMicrosoft2000 (including)2000 (including)
Biztalk_serverMicrosoft2000-sp1a (including)2000-sp1a (including)
Biztalk_serverMicrosoft2000-sp2 (including)2000-sp2 (including)
Biztalk_serverMicrosoft2002 (including)2002 (including)

References