CVE-2003-0874
Estado: ModificadaMedia (5)—
Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.37%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html
- http://marc.info/?l=bugtraq&m=106667525623311&w=2
- http://www.securiteam.com/unixfocus/6R0052K8KM.html
- http://www.securityfocus.com/bid/8856
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13391
- http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html
- http://marc.info/?l=bugtraq&m=106667525623311&w=2
- http://www.securiteam.com/unixfocus/6R0052K8KM.html
- http://www.securityfocus.com/bid/8856
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13391
JSON original (NVD)
Mostrar
{
"id": "CVE-2003-0874",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-11-17T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=106667525623311&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.securiteam.com/unixfocus/6R0052K8KM.html",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/8856",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/13391",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=106667525623311&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securiteam.com/unixfocus/6R0052K8KM.html",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/8856",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/13391",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen."
},
{
"lang": "es",
"value": "Múliples vulnerabilidades de inyección de SQL en DeskPRO 1.1.0 y anteriores permite a atacantes remotos insertar SQL arbitrario y llevar a cabo actividades no autorizadas mediante \r\nel parámetro cat en faq.php,\r\nel parámetro article n faq.php, \r\nel parámetro tickedid en view.php, y \r\nla entrada de contraseña en la pantalla de inicio de sesión."
}
],
"lastModified": "2026-06-16T22:03:07.210",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:deskpro:deskpro:1.1_.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A26AE575-32A3-42AB-ACF1-05637CAEB54A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}