peter bassill · operator
$ cve CVE-2003-0338 JSON

CVE-2003-0338 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.03% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2003-05-21
Last modified2026-06-16

Affected (2)

VendorProduct
wsmp3wsmp3 daemon
wsmp3wsmp3 web server

Public exploits

SourceTitleDate
exploit-dbWSMP3 0.0.x - Remote Command Execution2003-05-21

References

→ the Explorer  ·  watch your stack  ·  NVD