7.5

CVE-2003-0118

SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftBiztalk Server Version2000 Editiondeveloper
MicrosoftBiztalk Server Version2000 Editionenterprise
MicrosoftBiztalk Server Version2000 Editionstandard
MicrosoftBiztalk Server Version2000 Updatesp1a Editiondeveloper
MicrosoftBiztalk Server Version2000 Updatesp1a Editionenterprise
MicrosoftBiztalk Server Version2000 Updatesp1a Editionstandard
MicrosoftBiztalk Server Version2000 Updatesp2 Editiondeveloper
MicrosoftBiztalk Server Version2000 Updatesp2 Editionenterprise
MicrosoftBiztalk Server Version2000 Updatesp2 Editionstandard
MicrosoftBiztalk Server Version2002 Editiondeveloper
MicrosoftBiztalk Server Version2002 Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.09% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P