PT-2000-1145 · Microsoft · Site Server 3.0 Commerce Edition
Publicado
2000-02-18
·
Atualizado
2018-10-12
·
CVE-2000-0161
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Site Server 3.0 Commerce Edition
Description
The issue concerns sample web sites on Microsoft Site Server 3.0 Commerce Edition that do not validate an identification number. This lack of validation allows remote attackers to execute SQL commands.
Recommendations
For Microsoft Site Server 3.0 Commerce Edition, ensure that all identification numbers are properly validated to prevent the execution of unauthorized SQL commands. As a temporary workaround, consider restricting access to sensitive database operations until a proper validation mechanism is implemented.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Site Server 3.0 Commerce Edition