CVE-2003-1410 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 82)
Patch early
A public exploit exists.
Description
PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.26% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| isoca | cedric email reader |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cedric Email Reader 0.2/0.3 - Skin Configuration Script Remote File Inclusion | 2003-02-09 |
References
- http://secunia.com/advisories/8024
- http://www.osvdb.org/5487
- http://www.securityfocus.com/archive/1/311173
- http://www.securityfocus.com/bid/6818
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11278
- http://secunia.com/advisories/8024
- http://www.osvdb.org/5487
- http://www.securityfocus.com/archive/1/311173
- http://www.securityfocus.com/bid/6818
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11278
→ the Explorer · watch your stack · NVD