CVE-2003-0481

TUTOS 1.1 - Cross-Site Scripting via msg Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0481. PoCs published by François SORIN.

AI-analyzed exploit summary The exploit describes a cross-site scripting (XSS) vulnerability in Tutos' file_select.php script due to improper input handling. An attacker can inject hostile code via the 'msg' parameter to execute arbitrary JavaScript in the context of a user's browser session.

Description

Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by François SORIN · textwebappsphp
https://www.exploit-db.com/exploits/22818

The exploit describes a cross-site scripting (XSS) vulnerability in Tutos' file_select.php script due to improper input handling. An attacker can inject hostile code via the 'msg' parameter to execute arbitrary JavaScript in the context of a user's browser session.

Classification
Writeup 80%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Tutos (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Tutos file_select.php script
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105638743109781&w=2

Scores

EPSS 0.0297
EPSS Percentile 85.5%

Details

Status published
Products (1)
gero_kohnert/tutos 1.1
Published Aug 07, 2003
Tracked Since Feb 18, 2026