CVE-2003-0320

ttCMS < 2.3 - Remote Code Execution via Admin Parameter Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0320. PoCs published by [email protected].

AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in ttCMS due to insufficient sanitization of the 'admin_root' parameter in 'header.php'. An attacker can include a malicious PHP file from a remote server by manipulating the URL.

Description

header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/22612

This exploit demonstrates a remote file inclusion vulnerability in ttCMS due to insufficient sanitization of the 'admin_root' parameter in 'header.php'. An attacker can include a malicious PHP file from a remote server by manipulating the URL.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ttCMS (version not specified)
No auth needed
Prerequisites: Remote server hosting malicious PHP file · Network access to the target ttCMS installation
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105320172212990&w=2

Scores

EPSS 0.0533
EPSS Percentile 91.8%

Details

Status published
Products (1)
andy_prevost/ttcms < 2.3
Published Jun 09, 2003
Tracked Since Feb 18, 2026