CVE-2003-1410

Isoca Cedric Email Reader - Code Injection

Title source: rule
STIX 2.1

Description

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by MGhz · textwebappsphp
https://www.exploit-db.com/exploits/22241

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5487
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6818
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11278
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/311173
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/8024

Scores

EPSS 0.0450
EPSS Percentile 89.2%

Details

CWE
CWE-94
Status published
Products (2)
isoca/cedric_email_reader 0.2
isoca/cedric_email_reader 0.3
Published Dec 31, 2003
Tracked Since Feb 18, 2026