CVE-2003-1371 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 3.32% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| nuked-klan | nuked-klan |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Nuked-klaN 1.3 - Remote Information Disclosure | 2003-02-23 |
References
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html
- http://www.securityfocus.com/bid/6917
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11424
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html
- http://www.securityfocus.com/bid/6917
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11424
→ the Explorer · watch your stack · NVD