CVE detail
CVE-2002-0903 — CVE-2002-0903
Published 2002-10-04 · Modified 2026-06-16 · Vendor woltlab · Product burning_board · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0177
EPSS probability
exploitation probability, 30d
76.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID's, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References