peter bassill · operator
$ cve CVE-2003-1239 JSON

CVE-2003-1239 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS7.18% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
wihphotowihphoto

Public exploits

SourceTitleDate
exploit-dbWihPhoto 0.86 dev - 'sendphoto.php' File Disclosure2003-02-24

References

→ the Explorer  ·  watch your stack  ·  NVD