CVE-2003-0737
Published Oct 20, 2003
Last updated 8 years ago
Overview
- Description
- The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpwebsite:phpwebsite:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC96AC1E-CA99-49B6-8032-2664619C6D37", "versionEndIncluding": "0.9.0" } ], "operator": "OR" } ] } ]