Vulnerability Description
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Newsphp | Newsphp | <= 216 |
References
- http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.htmlExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.htmlExploitVendor Advisory
FAQ
What is CVE-2003-0754?
CVE-2003-0754 is a vulnerability with a CVSS score of 7.5 (HIGH). nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
How severe is CVE-2003-0754?
CVE-2003-0754 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0754?
Check the references section above for vendor advisories and patch information. Affected products include: Newsphp Newsphp.