CVE-2003-1350

List Site Pro - Improper Input Validation

Title source: rule
STIX 2.1

Description

List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Statix · textremotemultiple
https://www.exploit-db.com/exploits/22201

References (4)

Core 4
Core References
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/308300
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3230
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11156
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6685

Scores

EPSS 0.0554
EPSS Percentile 90.3%

Details

CWE
CWE-20
Status published
Products (1)
list_site_pro/list_site_pro 2.0
Published Dec 31, 2003
Tracked Since Feb 18, 2026