Sploitus

CVE-2003-0118

2 known exploits for CVE-2003-0118

SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.

Affected products
Biztalk Server
Microsoft Biztalk Server
= 2000, 2002
CVSS 2.0
7.5 HIGH
EPSS
8.1% (94th percentile)
NVD status
Modified
Published
2003-05-02
CVE-2003-0118 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2003-0118

Proof-of-concept code and exploit modules indexed by Sploitus