peter bassill · operator
$ cve CVE-2003-1371 JSON

CVE-2003-1371 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.32% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
nuked-klannuked-klan

Public exploits

SourceTitleDate
exploit-dbNuked-klaN 1.3 - Remote Information Disclosure2003-02-23

References

→ the Explorer  ·  watch your stack  ·  NVD