Back

CVE-2003-0585

SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.

Published: Aug 18, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
brooky estore 1.0.2b

GitHub Security Advisory GHSA-rfmc-v2gq-q3j6

SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.52%

Top 28% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub