CVE-2003-1239 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.2% (pctl 94)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 7.18% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| wihphoto | wihphoto |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WihPhoto 0.86 dev - 'sendphoto.php' File Disclosure | 2003-02-24 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html
- http://www.iss.net/security_center/static/11429.php
- http://www.securityfocus.com/archive/1/312966
- http://www.securityfocus.com/bid/6929
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html
- http://www.iss.net/security_center/static/11429.php
- http://www.securityfocus.com/archive/1/312966
- http://www.securityfocus.com/bid/6929
→ the Explorer · watch your stack · NVD