Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2003-1459

EPSS 2.90% · P86
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2003-1459

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ttCMS / ttForum远程文件包含漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ttCMS/ttForum是两款基于WEB的论坛程序。 ttCMS/ttForum包含的多个脚本对用户提供的输入缺少正确过滤,远程攻击者可以利用这个漏洞以WEB权限在系统上执行任意命令。 ttCMS/ttForum包含的modules/forum/News.php脚本包含如下代码: include($template . '.' . $ext); 此变量用于从用户输入中直接获得包含文件,由于没有进行初始化,因此可以通过全局注入来进行变量定义,攻击者可以指定远程系统中的PHP文件作为参数提交给$templa
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2003-1459

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-1459

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-10-23 · 66 CVEs total

CVE-2003-1438BEA Systems WebLogic Server和Express会话共享漏洞
CVE-2003-1457Auerswald COMsuite CTI应用程序弱默认密码漏洞
CVE-2003-1456Mike Bobbitt album.pl远程任意命令执行漏洞
CVE-2003-1455Poptop PPTP BCRELAY sprintf()本地缓冲区溢出漏洞
CVE-2003-1444Kaspersky Antivirus (KAV)漏洞
CVE-2003-1443Kaspersky Antivirus (KAV)病毒保护绕过漏洞
CVE-2003-1442HM220dp ADSL modem WEB管理接口不安全漏洞
CVE-2003-1441Posadis DNS请求问题区远程拒绝服务漏洞
CVE-2003-1440SpamProbe远程拒绝服务漏洞
CVE-2003-1439SILC Server SSH2本地内存中密码泄露漏洞
CVE-2003-1445RARLAB FAR文件管理器缓冲区溢出漏洞
CVE-2003-1437BEA WebLogic密钥库清除文本密码存储漏洞
CVE-2003-1436Nukebrowser远程包含漏洞
CVE-2003-1435PHP-Nuke modules.php远程可获取加密后口令漏洞
CVE-2003-1434login_ldap模块未授权访问漏洞
CVE-2003-1433Epic Games Unreal Engine多用户拒绝服务攻击漏洞
CVE-2003-1432Epic Games Unreal Engine内存消耗拒绝服务攻击漏洞
CVE-2003-1431Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞
CVE-2003-1430Epic Games Unreal Engine Unreal URL目录遍历漏洞
CVE-2003-1429Proxomitron Naoko缓冲区溢出漏洞

Showing top 20 of 66 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2003-1459

No comments yet


Leave a comment