CVE

Id
7205  
CVE No.
CVE-2003-0377  
Status
Candidate  
Description
SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.  
Phase
Assigned (20030604)  
Votes
None (candidate not yet proposed)  
Comments