CVE-2003-0979
Last modified
CVE-2003-0979 is a vulnerability of currently unknown severity. FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freescripts | Visitorbook | le |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0979?
How severe is CVE-2003-0979?
How do I fix CVE-2003-0979?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0973Unknown vulnerability in mod_python 3.0.x before 3.0.4, and …
- CVE-2003-0974Applied Watch Command Center allows remote attackers to cond…
- CVE-2003-0975Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X…
- CVE-2003-0976NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not proper…
- CVE-2003-0977CVS server before 1.11.10 may allow attackers to cause the C…
- CVE-2003-0978Format string vulnerability in gpgkeys_hkp (experimental HKP…
- CVE-2003-0980Cross-site scripting (XSS) vulnerability in FreeScripts Visi…
- CVE-2003-0981FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse…6.1
- CVE-2003-0982Buffer overflow in the authentication module for Cisco ACNS …
- CVE-2003-0983Cisco Unity on IBM servers is shipped with default settings …
- CVE-2003-0984Real time clock (RTC) routines in Linux kernel 2.4.23 and ea…
- CVE-2003-0985The mremap system call (do_mremap) in Linux kernel 2.4.x bef…
Are you affected by CVE-2003-0979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
