CVE-2000-0161

Microsoft Site Server 3.0 Commerce Edition - SQL Injection

Title source: llm
STIX 2.1

Description

Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/994

Scores

EPSS 0.1007
EPSS Percentile 95.2%

Details

Status published
Products (1)
microsoft/site_server 3.0
Published Feb 18, 2000
Tracked Since Feb 18, 2026