CVE-2003-0509 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 5.9% (pctl 93)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 5.86% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-08-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cyberstrong | eshop |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CyberStrong EShop 4.2 - '20review.asp' SQL Injection | 2005-06-30 |
| exploit-db | CyberStrong eShop 4.2 - '10expand.asp' SQL Injection | 2005-06-30 |
References
- http://marc.info/?l=bugtraq&m=105709450711395&w=2
- http://secunia.com/advisories/9165
- http://securitytracker.com/id?1007092
- http://www.osvdb.org/10098
- http://www.osvdb.org/10099
- http://www.osvdb.org/10100
- http://www.securityfocus.com/bid/14101
- http://www.securityfocus.com/bid/14103
- http://www.securityfocus.com/bid/14112
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12485
- http://marc.info/?l=bugtraq&m=105709450711395&w=2
- http://secunia.com/advisories/9165
- http://securitytracker.com/id?1007092
- http://www.osvdb.org/10098
- http://www.osvdb.org/10099
- http://www.osvdb.org/10100
- http://www.securityfocus.com/bid/14101
- http://www.securityfocus.com/bid/14103
- http://www.securityfocus.com/bid/14112
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12485
→ the Explorer · watch your stack · NVD