PT-2000-1145 · Microsoft · Site Server 3.0 Commerce Edition
Published
2000-02-18
·
Updated
2018-10-12
·
CVE-2000-0161
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Site Server 3.0 Commerce Edition
Description
The issue concerns sample web sites on Microsoft Site Server 3.0 Commerce Edition that do not validate an identification number. This lack of validation allows remote attackers to execute SQL commands.
Recommendations
For Microsoft Site Server 3.0 Commerce Edition, ensure that all identification numbers are properly validated to prevent the execution of unauthorized SQL commands. As a temporary workaround, consider restricting access to sensitive database operations until a proper validation mechanism is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Site Server 3.0 Commerce Edition