CVE-2003-0522
Last modified
CVE-2003-0522 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.. EPSS estimates a 1.87% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Early Impact | Productcart | 1.5 |
| Early Impact | Productcart | 1.6b |
| Early Impact | Productcart | 1.6b001 |
| Early Impact | Productcart | 1.6b002 |
| Early Impact | Productcart | 1.6b003 |
| Early Impact | Productcart | 1.6br |
| Early Impact | Productcart | 1.6br001 |
| Early Impact | Productcart | 1.6br003 |
| Early Impact | Productcart | 1.5002 |
| Early Impact | Productcart | 1.5003 |
| Early Impact | Productcart | 1.5003r |
| Early Impact | Productcart | 1.5004 |
| Early Impact | Productcart | 1.6002 |
| Early Impact | Productcart | 1.6003 |
| Early Impact | Productcart | 2 |
| Early Impact | Productcart | 2br000 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0522?
How severe is CVE-2003-0522?
How do I fix CVE-2003-0522?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0516cnd.c in mgetty 1.1.28 and earlier does not properly filter …
- CVE-2003-0517faxrunqd.in in mgetty 1.1.28 and earlier allows local users …5.5
- CVE-2003-0518The screen saver in MacOS X allows users with physical acces…
- CVE-2003-0519Certain versions of Internet Explorer 5 and 6, in certain Wi…
- CVE-2003-0520Trillian 1.0 Pro and 0.74 Freeware allows remote attackers t…
- CVE-2003-0521Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 all…
- CVE-2003-0523Cross-site scripting (XSS) vulnerability in msg.asp for cert…
- CVE-2003-0524Qt in Knoppix 3.1 Live CD allows local users to overwrite ar…
- CVE-2003-0525The getCanonicalPath function in Windows NT 4.0 may free mem…
- CVE-2003-0526Cross-site scripting (XSS) vulnerability in Microsoft Intern…
- CVE-2003-0528Heap-based buffer overflow in the Distributed Component Obje…
- CVE-2003-0530Buffer overflow in the BR549.DLL ActiveX control for Interne…
Are you affected by CVE-2003-0522?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
