« Volver al listado

CVE-2003-0491

Estado: ModificadaAlta (7.5)—

The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-0491",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2003-08-07T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=vuln-dev&m=105577873506147&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file."
    },
    {
      "lang": "es",
      "value": "El módulo Tutorials 2.0 en XOOPS y E-XOOPS no comprueba el tipo MIME cuando se suben imágenes, y permite a atancantes remotos ejecutar código arbitario subiendo un fichero PHP en lugar de una imagen, y entonces accediendo directamente al fichero subido mediante una petición HTTP."
    }
  ],
  "lastModified": "2026-06-16T22:02:18.313",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mytutorials:tutorials:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8738ED82-73D2-4AE9-BF47-0C51011F9963"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}