{"api_version":"1","generated_at":"2026-07-23T07:32:24+00:00","cve":"CVE-2003-1268","urls":{"html":"https://cve.report/CVE-2003-1268","api":"https://cve.report/api/cve/CVE-2003-1268.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1268","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1268"},"summary":{"title":"CVE-2003-1268","description":"Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securitytracker.com/id?1005903","name":"http://www.securitytracker.com/id?1005903","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"a.shopKart Input Validation Flaw Permits SQL Command Injection and Discloses Shopping Database Information to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/37037","name":"http://www.osvdb.org/37037","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.iss.net/security_center/static/11029.php","name":"http://www.iss.net/security_center/static/11029.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:ashopkart-multiple-sql-injection(11029): a.shopKart multiple SQL injection","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.osvdb.org/37038","name":"http://www.osvdb.org/37038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/305685","name":"http://www.securityfocus.com/archive/1/305685","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/7838","name":"http://secunia.com/advisories/7838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - a.shopKart sql injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/37036","name":"http://www.osvdb.org/37036","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/6558","name":"http://www.securityfocus.com/bid/6558","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"A.ShopKart Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.centaura.com.ar/infosec/adv/ashopkart.txt","name":"http://www.centaura.com.ar/infosec/adv/ashopkart.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1268","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1268","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"urlogy","cpe5":"a.shop.kart","cpe6":"2.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:19:46.121Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ashopkart-multiple-sql-injection(11029)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/11029.php"},{"name":"6558","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6558"},{"name":"37036","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/37036"},{"name":"37038","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/37038"},{"name":"37037","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/37037"},{"name":"20030108 a.shopKart Shopping Cart remote vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/305685"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.centaura.com.ar/infosec/adv/ashopkart.txt"},{"name":"7838","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/7838"},{"name":"1005903","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1005903"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-01-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-10-31T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ashopkart-multiple-sql-injection(11029)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/11029.php"},{"name":"6558","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6558"},{"name":"37036","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/37036"},{"name":"37038","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/37038"},{"name":"37037","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/37037"},{"name":"20030108 a.shopKart Shopping Cart remote vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/305685"},{"tags":["x_refsource_MISC"],"url":"http://www.centaura.com.ar/infosec/adv/ashopkart.txt"},{"name":"7838","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/7838"},{"name":"1005903","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1005903"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1268","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ashopkart-multiple-sql-injection(11029)","refsource":"XF","url":"http://www.iss.net/security_center/static/11029.php"},{"name":"6558","refsource":"BID","url":"http://www.securityfocus.com/bid/6558"},{"name":"37036","refsource":"OSVDB","url":"http://www.osvdb.org/37036"},{"name":"37038","refsource":"OSVDB","url":"http://www.osvdb.org/37038"},{"name":"37037","refsource":"OSVDB","url":"http://www.osvdb.org/37037"},{"name":"20030108 a.shopKart Shopping Cart remote vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/305685"},{"name":"http://www.centaura.com.ar/infosec/adv/ashopkart.txt","refsource":"MISC","url":"http://www.centaura.com.ar/infosec/adv/ashopkart.txt"},{"name":"7838","refsource":"SECUNIA","url":"http://secunia.com/advisories/7838"},{"name":"1005903","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1005903"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1268","datePublished":"2005-11-16T07:37:00.000Z","dateReserved":"2005-11-16T00:00:00.000Z","dateUpdated":"2024-08-08T02:19:46.121Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:urlogy:a.shop.kart:2.0.3:*:*:*:*:*:*:*","matchCriteriaId":"5F9F6277-509B-4574-BC83-F4CEF20FD020"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1268","Ordinal":"1","Title":"CVE-2003-1268","CVE":"CVE-2003-1268","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1268","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.","Type":"Description","Title":"CVE-2003-1268"},{"CveYear":"2003","CveId":"1268","Ordinal":"2","NoteData":"2005-11-16","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1268","Ordinal":"3","NoteData":"2007-10-31","Type":"Other","Title":"Modified"}]}}}