← All CVEs

CVE-2003-0770

high · 7.5

FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.

7.5
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2003-09-22
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
ikonboard.comikonboard3.1.1
ikonboard.comikonboard3.1.2a

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0770