CVE-2004-1448
UnknownEPSS 1.69%
Last modified
CVE-2004-1448 is a vulnerability of currently unknown severity. Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.. EPSS estimates a 1.69% chance of exploitation in the next 30 days.
Description
Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jetbox | Jetbox One Cms | 2.0.8 |
References
- http://www.kb.cert.org/vuls/id/417408Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/417408Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1448?
Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.
How severe is CVE-2004-1448?
Severity scoring for CVE-2004-1448 is pending analysis. The EPSS model estimates a 1.69% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1448?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1442Cross-site scripting (XSS) vulnerability in db2www CGI inter…
- CVE-2004-1443Cross-site scripting (XSS) vulnerability in the inline MIME …
- CVE-2004-1444Directory traversal vulnerability in Roundup 0.6.4 and earli…
- CVE-2004-1445A race condition in nessus-adduser in Nessus 2.0.11 and poss…
- CVE-2004-1446Unknown vulnerability in ScreenOS in Juniper Networks NetScr…
- CVE-2004-1447Jetbox One 2.0.8 and possibly other versions stores password…
- CVE-2004-1449Mozilla before 1.7, Firefox before 0.9, and Thunderbird befo…
- CVE-2004-1450Unknown vulnerability in LiveConnect in Mozilla 1.7 beta all…
- CVE-2004-1451Mozilla before 1.6 does not display the entire URL in the st…
- CVE-2004-1452Tomcat before 5.0.27-r3 in Gentoo Linux sets the default per…
- CVE-2004-1453GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20…
- CVE-2004-1454Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path Fir…
Are you affected by CVE-2004-1448?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
