peter bassill · operator
$ cve CVE-2002-1499 JSON

CVE-2002-1499 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.48% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-02
Last modified2026-06-16

Affected (1)

VendorProduct
factosystemfactosystem weblog

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD