« Volver al listado

CVE-2003-0599

Estado: ModificadaAlta (10)—

Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web document root.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-0599",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2003-08-27T04:00:00.000",
  "references": [
    {
      "url": "http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2003/dsa-365",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.phpgroupware.org",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2003/dsa-365",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.phpgroupware.org",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web document root."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad desconocida en la capacidad de Sistema de Ficheros Virtual (VFS) de phpGroupWare 0.9.16preRC, y versiones anteriores a 0.9.14.004 con implicaciones desconocidas, relacionadas con que la ruta VFS esté bajo la raíz de documentos web."
    }
  ],
  "lastModified": "2026-06-16T22:02:29.777",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpgroupware:phpgroupware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0B79024-B9B4-4FE1-A734-4729D26DB5CD",
              "versionEndIncluding": "0.9.14.004"
            },
            {
              "criteria": "cpe:2.3:a:phpgroupware:phpgroupware:0.9.16prerc:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D8DDA15-ED21-498E-94BB-2998968139D7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}