CVE-2002-1499
Summary
| CVE | CVE-2002-1499 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-04-02 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Factosystem | Factosystem Weblog | 0.9b | All | All | All |
| Application | Factosystem | Factosystem Weblog | 1.0_beta | All | All | All |
| Application | Factosystem | Factosystem Weblog | 1.1_beta | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Exploit, Vendor Advisory |
| FactoSystem Weblog Multiple SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| Neohapsis Archives - VulnWatch - [VulnWatch] FactoSystem CMS Contains Multiple Vulnerabilities - From mattmurphy_at_kc.rr.com | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| FactoSystem Weblog (ASP based) / Bugs / #7 SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| ISS X-Force Database: factosystem-asp-sql-injection (10000): FactoSystem multiple ASP SQL injection | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.