Back

CVE-2003-0509

SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.

Published: Aug 7, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
cyberstrong eshop *

GitHub Security Advisory GHSA-4f2q-36fr-vgv3

SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 5.85%

Top 7% most likely to be exploited

Threat Score 41.8 / 100

Data Sources

NVD EPSS GitHub