Vulnerability Description
aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| E-Theni | E-Theni | All versions |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.htmlExploitPatch
- http://www.iss.net/security_center/static/11013.php
- http://www.securityfocus.com/archive/1/305381ExploitPatch
- http://www.securityfocus.com/bid/6970Exploit
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.htmlExploitPatch
- http://www.iss.net/security_center/static/11013.php
- http://www.securityfocus.com/archive/1/305381ExploitPatch
- http://www.securityfocus.com/bid/6970Exploit
FAQ
What is CVE-2003-1256?
CVE-2003-1256 is a vulnerability with a CVSS score of 6.8 (MEDIUM). aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.
How severe is CVE-2003-1256?
CVE-2003-1256 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1256?
Check the references section above for vendor advisories and patch information. Affected products include: E-Theni E-Theni.