Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0377


Vulnerability Score 7.5 7.5
CVE Id CVE-2003-0377
Last Modified 05 Sep 2008 04:34:10
Published 16 Jun 2003 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.

Vulnerable Systems


  • Iisprotect 2.2 R4


BUGTRAQ - 20030523 iisPROTECT SQL injection in admin interface

Last Updated: 27 May 2016 10:37:53