CVE-2003-0395
Last modified
CVE-2003-0395 is a vulnerability of currently unknown severity. Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.. EPSS estimates a 2.53% chance of exploitation in the next 30 days.
Description
Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Myupb | Ultimate Php Board | 1.9 |
References
- http://f0kp.iplus.ru/bz/024.en.txtBroken Link
- http://marc.info/?l=bugtraq&m=105379741528925&w=2Third Party Advisory
- http://f0kp.iplus.ru/bz/024.en.txtBroken Link
- http://marc.info/?l=bugtraq&m=105379741528925&w=2Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0395?
How severe is CVE-2003-0395?
How do I fix CVE-2003-0395?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0389Cross-site scripting (XSS) vulnerability in the secure redir…
- CVE-2003-0390Multiple buffer overflows in Options Parsing Tool (OPT) shar…
- CVE-2003-0391Format string vulnerability in Magic WinMail Server 2.3, and…
- CVE-2003-0392Directory traversal vulnerability in ST FTP Service 3.0 allo…
- CVE-2003-0393Privacyware Privatefirewall 3.0 does not block certain incom…
- CVE-2003-0394objects.inc.php4 in BLNews 2.1.3 allows remote attackers to …
- CVE-2003-0396Buffer overflow in les for ATM on Linux (linux-atm) before 2…
- CVE-2003-0397Buffer overflow in FastTrack (FT) network code, as used in K…
- CVE-2003-0398Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with…
- CVE-2003-0399Vignette StoryServer 4 and 5, Vignette V/5, and possibly oth…
- CVE-2003-0400Vignette StoryServer and Vignette V/5 does not properly calc…
- CVE-2003-0401Vignette StoryServer and Vignette V/5 allows remote attacker…
Are you affected by CVE-2003-0395?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
