7.5
CVSSv2

CVE-2003-0320

Published: 09/06/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

header.php in ttCMS 2.3 and previous versions allows remote malicious users to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.

Vulnerable Product Search on Vulmon Subscribe to Product

andy prevost ttcms

Exploits

source: wwwsecurityfocuscom/bid/7625/info A remote file include vulnerability has been reported for ttCMS Due to insufficient sanitization of some user-supplied variables by the 'headerphp' script, it is possible for a remote attacker to include a malicious PHP file in a URL target/admin/templates/headerphp?admin_root= ...