CVE-2003-1412 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.69% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gonicus | gonicus system administration |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GONiCUS System Administrator 1.0 - Remote File Inclusion | 2003-02-24 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003932.html
- http://secunia.com/advisories/8120
- http://www.securityfocus.com/archive/1/313282/30/25760/threaded
- http://www.securityfocus.com/bid/6922
- http://www.securitytracker.com/id?1006162
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11408
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003932.html
- http://secunia.com/advisories/8120
- http://www.securityfocus.com/archive/1/313282/30/25760/threaded
- http://www.securityfocus.com/bid/6922
- http://www.securitytracker.com/id?1006162
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11408
→ the Explorer · watch your stack · NVD