{"api_version":"1","generated_at":"2026-07-23T04:54:31+00:00","cve":"CVE-2003-0509","urls":{"html":"https://cve.report/CVE-2003-0509","api":"https://cve.report/api/cve/CVE-2003-0509.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0509","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0509"},"summary":{"title":"CVE-2003-0509","description":"SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-08-07 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=105709450711395&w=2","name":"http://marc.info/?l=bugtraq&m=105709450711395&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'CyberStrong Shopping Cart - Advisory & Exploit Code' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1007092","name":"http://securitytracker.com/id?1007092","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - CyberStrong eShop Lets Remote Users Inject SQL Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14101","name":"http://www.securityfocus.com/bid/14101","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CyberStrong EShop 20review.ASP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/10098","name":"http://www.osvdb.org/10098","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/10099","name":"http://www.osvdb.org/10099","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12485","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12485","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/9165","name":"http://secunia.com/advisories/9165","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - CyberStrong eShop SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14112","name":"http://www.securityfocus.com/bid/14112","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CyberStrong EShop 10browse.ASP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/10100","name":"http://www.osvdb.org/10100","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/14103","name":"http://www.securityfocus.com/bid/14103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CyberStrong eShop 10expand.ASP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0509","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0509","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"509","vulnerable":"1","versionEndIncluding":"4.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cyberstrong","cpe5":"eshop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:58:11.111Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20030701 CyberStrong Shopping Cart - Advisory & Exploit Code","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=105709450711395&w=2"},{"name":"14103","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14103"},{"name":"10099","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/10099"},{"name":"cyberstrongeshop-multiple-sql-injection(12485)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12485"},{"name":"14101","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14101"},{"name":"10100","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/10100"},{"name":"1007092","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1007092"},{"name":"14112","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14112"},{"name":"10098","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/10098"},{"name":"9165","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/9165"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-07-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20030701 CyberStrong Shopping Cart - Advisory & Exploit Code","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=105709450711395&w=2"},{"name":"14103","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14103"},{"name":"10099","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/10099"},{"name":"cyberstrongeshop-multiple-sql-injection(12485)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12485"},{"name":"14101","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14101"},{"name":"10100","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/10100"},{"name":"1007092","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1007092"},{"name":"14112","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14112"},{"name":"10098","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/10098"},{"name":"9165","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/9165"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0509","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20030701 CyberStrong Shopping Cart - Advisory & Exploit Code","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=105709450711395&w=2"},{"name":"14103","refsource":"BID","url":"http://www.securityfocus.com/bid/14103"},{"name":"10099","refsource":"OSVDB","url":"http://www.osvdb.org/10099"},{"name":"cyberstrongeshop-multiple-sql-injection(12485)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12485"},{"name":"14101","refsource":"BID","url":"http://www.securityfocus.com/bid/14101"},{"name":"10100","refsource":"OSVDB","url":"http://www.osvdb.org/10100"},{"name":"1007092","refsource":"SECTRACK","url":"http://securitytracker.com/id?1007092"},{"name":"14112","refsource":"BID","url":"http://www.securityfocus.com/bid/14112"},{"name":"10098","refsource":"OSVDB","url":"http://www.osvdb.org/10098"},{"name":"9165","refsource":"SECUNIA","url":"http://secunia.com/advisories/9165"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0509","datePublished":"2003-07-04T04:00:00.000Z","dateReserved":"2003-07-03T00:00:00.000Z","dateUpdated":"2024-08-08T01:58:11.111Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-08-07 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cyberstrong:eshop:*:*:*:*:*:*:*:*","versionEndIncluding":"4.2","matchCriteriaId":"3D9F816B-410A-4418-947E-364403E9A186"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"509","Ordinal":"1","Title":"CVE-2003-0509","CVE":"CVE-2003-0509","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"509","Ordinal":"1","NoteData":"SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.","Type":"Description","Title":"CVE-2003-0509"},{"CveYear":"2003","CveId":"509","Ordinal":"2","NoteData":"2003-07-04","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"509","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}