First published: Fri Feb 18 2000(Updated: )
Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Site Server Commerce | =3.0 | |
=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0161 is considered high due to the potential for remote SQL command execution.
To fix CVE-2000-0161, apply the Microsoft Site Server 3.0 Commerce Edition patch provided by Microsoft.
CVE-2000-0161 can lead to unauthorized access and manipulation of the database by executing arbitrary SQL commands.
CVE-2000-0161 affects users operating Microsoft Site Server 3.0 Commerce Edition.
To determine vulnerability to CVE-2000-0161, check if you are using Microsoft Site Server version 3.0 and review your SQL command validation practices.