CVE-2002-1499

FactoSystem Weblog - SQL Injection via authornumber, discussblurbid, name, or email Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1499. PoCs published by Matthew Murphy.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in FactoSystem Weblog. The crafted URL manipulates the 'authornumber' parameter to execute arbitrary SQL commands, including updating the 'root' user's password.

Description

Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matthew Murphy · textwebappsasp
https://www.exploit-db.com/exploits/21766

This exploit demonstrates a SQL injection vulnerability in FactoSystem Weblog. The crafted URL manipulates the 'authornumber' parameter to execute arbitrary SQL commands, including updating the 'root' user's password.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: FactoSystem Weblog
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10000.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5600
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0097.html
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/290021

Scores

EPSS 0.0248
EPSS Percentile 82.5%

Details

Status published
Products (3)
factosystem/factosystem_weblog 0.9b
factosystem/factosystem_weblog 1.0_beta
factosystem/factosystem_weblog 1.1_beta
Published Apr 02, 2003
Tracked Since Feb 18, 2026