CVE detail
CVE-2003-0320 — CVE-2003-0320
Published 2003-06-09 · Modified 2026-06-16 · Vendor andy_prevost · Product ttcms · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0533
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References