peter bassill · operator
$ cve CVE-2003-1550 JSON

CVE-2003-1550 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.89% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
xoopsxoops

Public exploits

SourceTitleDate
exploit-dbXOOPS 2.0 XoopsOption - Information Disclosure2003-03-20

References

→ the Explorer  ·  watch your stack  ·  NVD