PT-2000-1145 · Microsoft · Site Server 3.0 Commerce Edition

Publicado

2000-02-18

·

Atualizado

2018-10-12

·

CVE-2000-0161

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Site Server 3.0 Commerce Edition
Description The issue concerns sample web sites on Microsoft Site Server 3.0 Commerce Edition that do not validate an identification number. This lack of validation allows remote attackers to execute SQL commands.
Recommendations For Microsoft Site Server 3.0 Commerce Edition, ensure that all identification numbers are properly validated to prevent the execution of unauthorized SQL commands. As a temporary workaround, consider restricting access to sensitive database operations until a proper validation mechanism is implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0161

Produtos afetados

Site Server 3.0 Commerce Edition