CVE-2003-1537: Path Traversal
Published Dec 31, 2003
·Updated
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke<=0.723
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Nov 14, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1537?
CVE-2003-1537 is considered a critical vulnerability due to its potential for remote code execution through directory traversal.
2
How do I fix CVE-2003-1537?
To fix CVE-2003-1537, update PostNuke to version 0.724 or later to eliminate the directory traversal vulnerability.
3
What systems are affected by CVE-2003-1537?
CVE-2003-1537 affects PostNuke versions 0.723 and earlier.
4
What type of attack does CVE-2003-1537 allow?
CVE-2003-1537 allows remote attackers to include arbitrary files through a maliciously crafted theme parameter.
5
Can CVE-2003-1537 be exploited without authentication?
Yes, CVE-2003-1537 can be exploited by unauthenticated attackers, making it particularly dangerous.