Snitz Forum < SQL Injection

High Nessus Network Monitor Plugin ID 5105


The remote host is vulnerable to a SQL Injection attack


The remote host seems to be running Snitz Forum, a web forum application implemented in ASP. This version of Snitz is reported vulnerable to a SQL injection flaw within the 'email' parameter of the 'register.asp' script. An attacker, exploiting this flaw, would send specially formed HTTP queries to the register.asp script. These queries would include SQL statements which would ultimately be executed on the database utilized by Snitz.


Upgrade to Snitz Forum or higher

See Also

Plugin Details

Severity: High

ID: 5105

Family: CGI

Published: 2007/07/29

Modified: 2016/01/15

Dependencies: 1442

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 7.3

Temporal Score: 6.8


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

Patch Publication Date: 2007/07/23

Vulnerability Publication Date: 2007/07/23

Reference Information

CVE: CVE-2003-0286

BID: 35764