CVE-2004-1843
published 2004-03-20CVE-2004-1843: SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2)…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
1.24%
65.4th percentile
SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Expinion.net Member Management System 2.1 - 'resend.asp?ID' SQL Injection
exploitdb·2004-03-20
CVE-2004-1843 Expinion.net Member Management System 2.1 - 'resend.asp?ID' SQL Injection
Expinion.net Member Management System 2.1 - 'resend.asp?ID' SQL Injection
---
source: https://www.securityfocus.com/bid/9931/info
It has been reported that Member Management System may be prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries. The problem is reported to exist in the 'ID' parameter contained within the 'resend.asp' and 'news_view.asp' scripts.
Member Management System version 2.1 has been reported to be affected by this issue, however, other versions may be vulnerable as well.
http://www.example.com/resend.asp?ID=[SQL query]
Exploit-DB
Expinion.net Member Management System 2.1 - 'news_view.asp?ID' SQL Injection
exploitdb·2004-03-20
CVE-2004-1843 Expinion.net Member Management System 2.1 - 'news_view.asp?ID' SQL Injection
Expinion.net Member Management System 2.1 - 'news_view.asp?ID' SQL Injection
---
source: https://www.securityfocus.com/bid/9931/info
It has been reported that Member Management System may be prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries. The problem is reported to exist in the 'ID' parameter contained within the 'resend.asp' and 'news_view.asp' scripts.
Member Management System version 2.1 has been reported to be affected by this issue, however, other versions may be vulnerable as well.
http://www.example.com/news_view.asp?ID=[SQL query]
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=107999697625786&w=2http://secunia.com/advisories/11179http://securitytracker.com/id?1009508http://www.securityfocus.com/bid/9931https://exchange.xforce.ibmcloud.com/vulnerabilities/15551http://marc.info/?l=bugtraq&m=107999697625786&w=2http://secunia.com/advisories/11179http://securitytracker.com/id?1009508http://www.securityfocus.com/bid/9931https://exchange.xforce.ibmcloud.com/vulnerabilities/15551
2004-03-20
Published