PT-2000-1145 · Microsoft · Site Server 3.0 Commerce Edition

Published

2000-02-18

·

Updated

2018-10-12

·

CVE-2000-0161

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Site Server 3.0 Commerce Edition
Description The issue concerns sample web sites on Microsoft Site Server 3.0 Commerce Edition that do not validate an identification number. This lack of validation allows remote attackers to execute SQL commands.
Recommendations For Microsoft Site Server 3.0 Commerce Edition, ensure that all identification numbers are properly validated to prevent the execution of unauthorized SQL commands. As a temporary workaround, consider restricting access to sensitive database operations until a proper validation mechanism is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0161

Affected Products

Site Server 3.0 Commerce Edition