CVE-2003-0395
Last modified
CVE-2003-0395 is a vulnerability of currently unknown severity. Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.. EPSS estimates a 2.53% chance of exploitation in the next 30 days.
Description
Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Myupb | Ultimate Php Board | 1.9 |
References
- http://f0kp.iplus.ru/bz/024.en.txtBroken Link
- http://marc.info/?l=bugtraq&m=105379741528925&w=2Third Party Advisory
- http://f0kp.iplus.ru/bz/024.en.txtBroken Link
- http://marc.info/?l=bugtraq&m=105379741528925&w=2Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0395?
How severe is CVE-2003-0395?
How do I fix CVE-2003-0395?
Are you affected by CVE-2003-0395?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
