CVE-2003-0275: Medium severity Yabb Yabb vulnerability
Published May 14, 2003
·Updated
SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.
Affected Software
1 affected component
Yabb Yabb=1.5.2
Event History
May 14, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 16, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0275?
CVE-2003-0275 is categorized as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2003-0275?
To fix CVE-2003-0275, upgrade YaBB SE to a version later than 1.5.2 that addresses this vulnerability.
3
What type of attack does CVE-2003-0275 enable?
CVE-2003-0275 enables remote attackers to execute arbitrary PHP code on the server.
4
Which version of YaBB is affected by CVE-2003-0275?
YaBB SE version 1.5.2 is the only affected version by CVE-2003-0275.
5
Is CVE-2003-0275 still a threat today?
While CVE-2003-0275 specifically targets an outdated version of YaBB, the underlying issue of remote code execution remains a relevant threat in web applications.