VulnerabilityModified
CVE-2003-1410
PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.
MEDIUM 6.8EPSS 2.26%
Does this matter?
Lower severity and a low EPSS score (2.26%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.26% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- isoca/cedric email reader
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/8024
- http://www.osvdb.org/5487
- http://www.securityfocus.com/archive/1/311173Exploit
- http://www.securityfocus.com/bid/6818Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11278
- http://secunia.com/advisories/8024
- http://www.osvdb.org/5487
- http://www.securityfocus.com/archive/1/311173Exploit
- http://www.securityfocus.com/bid/6818Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11278
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.