CVE-2003-1412: Code Injection
PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1412?
CVE-2003-1412 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2003-1412?
To fix CVE-2003-1412, update GONiCUS System Administrator to a patched version that addresses this vulnerability.
What systems are affected by CVE-2003-1412?
CVE-2003-1412 affects GONiCUS System Administration version 1.0.
What type of vulnerability is CVE-2003-1412?
CVE-2003-1412 is classified as a remote file inclusion vulnerability.
Can CVE-2003-1412 be exploited without authentication?
Yes, CVE-2003-1412 can be exploited by remote attackers without requiring authentication.