peter bassill · operator
$ cve CVE-2003-1459 JSON

CVE-2003-1459 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS7.07% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (2)

VendorProduct
ttcmsttcms
ttcmsttforum

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD