PT-2003-2404 · Tt+1 · Ttforum+2

Published

2003-12-31

·

Updated

2017-07-29

·

CVE-2003-1459

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ttCMS version 2.2 ttForum version 2.2
Description The issue concerns remote file inclusion vulnerabilities. These vulnerabilities allow remote attackers to execute arbitrary PHP code. The vulnerabilities can be exploited via the template parameter in News.php or the installdir parameter in install.php.
Recommendations For ttCMS version 2.2, consider disabling the News.php and install.php scripts until a patch is available. For ttForum version 2.2, restrict access to the News.php and install.php scripts to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1459

Affected Products

Php
Ttcms
Ttforum