CVE-2003-1555

Scoznet Scozbook - Information Disclosure

Title source: rule
STIX 2.1

Description

ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by euronymous · textwebappsphp
https://www.exploit-db.com/exploits/22445

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/7236
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/316747/30/25280/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/8476
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11659
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3781
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1006413

Scores

EPSS 0.0577
EPSS Percentile 90.5%

Details

CWE
CWE-200
Status published
Products (1)
scoznet/scozbook 1.1_beta
Published Dec 31, 2003
Tracked Since Feb 18, 2026