CVE-2003-0118 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 8.1% (pctl 95)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 8.14% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-05-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | biztalk server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft BizTalk Server 2000/2002 DTA - 'rawdocdata.asp' SQL Injection | 2003-04-30 |
| exploit-db | Microsoft BizTalk Server 2000/2002 DTA - 'RawCustomSearchField.asp' SQL Injection | 2003-04-30 |
References
→ the Explorer · watch your stack · NVD