peter bassill · operator
$ cve CVE-2003-1176 JSON

CVE-2003-1176 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS7.18% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
bdc enterprisesweb wiz forums

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD