CVE-2003-0509 is a critical SQL injection vulnerability affecting Cyberstrong eShop versions 4.2 and earlier, specifically targeting the ProductCode parameter within scripts such as 10expand.asp and 20review.asp. With a maximum CVSS score of 10.0, this flaw allows unauthenticated remote attackers to execute arbitrary database commands via a low-complexity network vector, potentially resulting in full data theft and privilege escalation. While proof-of-concept exploit code is publicly available on ExploitDB, there is currently no evidence of active exploitation in the wild or significant community discussion regarding this legacy vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2CPE matchmatch criteria | cpe:2.3:a:cyberstrong:eshop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.