CVE-2003-0395 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.53% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-07-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| myupb | ultimate php board |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ultimate PHP Board 1.9 - 'admin_iplog.php' Arbitrary PHP Execution | 2003-05-24 |
References
→ the Explorer · watch your stack · NVD