PoC Index

CVE-2002-1499

HIGH 7.5EPSS 2.5%

Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.48% chance of exploitation in the next 30 days, 83th percentile
Published
2003-03-18
Updated
2024-08-08

ExploitDB entries (1)

References

Related