CVE-2003-1405

DotBr 0.1 - Remote Command Execution via cmd Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2003-1405. PoCs published by frog.

AI-analyzed exploit summary The exploit describes a remote command execution vulnerability in DotBr's 'system.php3' script due to insufficient input sanitization. It provides a URL example for exploitation but lacks actual PoC code.

Description

DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.

Exploits (2)

exploitdb WRITEUP VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/22253

The exploit describes a remote command execution vulnerability in DotBr's 'system.php3' script due to insufficient input sanitization. It provides a URL example for exploitation but lacks actual PoC code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: DotBr system.php3
No auth needed
Prerequisites: Access to the vulnerable 'system.php3' script
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/22254

The exploit demonstrates a remote command execution vulnerability in DotBr's 'exec.php3' script due to insufficient input sanitization. An attacker can execute arbitrary shell commands by appending them to the 'cmd' parameter in the URL.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: DotBr exec.php3
No auth needed
Prerequisites: Access to the vulnerable 'exec.php3' script
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6866
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5089
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5090
Exploit mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11355
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6867

Scores

EPSS 0.0398
EPSS Percentile 89.1%

Details

CWE
CWE-20
Status published
Products (1)
dotbr/botbr 0.1
Published Dec 31, 2003
Tracked Since Feb 18, 2026