SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.
References
Link Resource
http://marc.info/?l=bugtraq&m=105370528728225&w=2 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2003-06-06T04:00:00

Updated: 2016-10-17T13:57:01

Reserved: 2003-06-04T00:00:00


Link: CVE-2003-0377

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2003-06-16T04:00:00.000

Modified: 2024-02-13T16:47:26.647


Link: CVE-2003-0377

JSON object: View

cve-icon Redhat Information

No data.

CWE