CVE-2003-0482

TUTOS 1.1 - Remote Code Execution via File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0482. PoCs published by François SORIN.

AI-analyzed exploit summary The exploit describes an arbitrary file upload vulnerability in Tutos via the file_new script, allowing attackers to upload files to a vulnerable site. The path structure for accessing uploaded files is provided.

Description

TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.

Exploits (1)

exploitdb WRITEUP VERIFIED
by François SORIN · textwebappsphp
https://www.exploit-db.com/exploits/22819

The exploit describes an arbitrary file upload vulnerability in Tutos via the file_new script, allowing attackers to upload files to a vulnerable site. The path structure for accessing uploaded files is provided.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Tutos (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Tutos instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105638743109781&w=2

Scores

EPSS 0.0713
EPSS Percentile 93.5%

Details

Status published
Products (1)
gero_kohnert/tutos 1.1
Published Aug 07, 2003
Tracked Since Feb 18, 2026