CVE-2003-0735: SQL Injection
Published Sep 4, 2003
·Updated
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.
Affected Software
1 affected component
phpWebSite phpWebSite<=0.9.0
Event History
Sep 4, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Oct 20, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0735?
CVE-2003-0735 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary SQL queries.
2
How do I fix CVE-2003-0735?
To fix CVE-2003-0735, upgrade to the latest version of phpWebSite that is not affected by the SQL injection vulnerability.
3
What software is affected by CVE-2003-0735?
CVE-2003-0735 affects phpWebSite version 0.9.x and earlier.
4
How does CVE-2003-0735 exploit SQL injection?
CVE-2003-0735 exploits SQL injection by manipulating the year parameter to execute arbitrary SQL commands on the database.
5
Can CVE-2003-0735 be exploited remotely?
Yes, CVE-2003-0735 can be exploited remotely, allowing attackers to compromise the targeted system.