{"api_version":"1","generated_at":"2026-07-23T11:08:38+00:00","cve":"CVE-2003-1212","urls":{"html":"https://cve.report/CVE-2003-1212","api":"https://cve.report/api/cve/CVE-2003-1212.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1212","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1212"},"summary":{"title":"CVE-2003-1212","description":"MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12278","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/8979","name":"http://secunia.com/advisories/8979","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Secunia - Advisories - MaxWebPortal Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7837","name":"http://www.securityfocus.com/bid/7837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Multiple MaxWebPortal Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html","name":"http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Neohapsis Archives - Bugtraq - #0048 - Critical Vulnerabilities In Max Web Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.osvdb.org/4933","name":"http://www.osvdb.org/4933","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1212","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1212","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1212","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxwebportal","cpe5":"maxwebportal","cpe6":"1.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:19:45.940Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"maxwebportal-form-field-modify(12278)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12278"},{"name":"7837","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7837"},{"name":"4933","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/4933"},{"name":"8979","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/8979"},{"name":"20030606 Critical Vulnerabilities In Max Web Portal","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-06-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"maxwebportal-form-field-modify(12278)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12278"},{"name":"7837","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7837"},{"name":"4933","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/4933"},{"name":"8979","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/8979"},{"name":"20030606 Critical Vulnerabilities In Max Web Portal","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1212","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"maxwebportal-form-field-modify(12278)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12278"},{"name":"7837","refsource":"BID","url":"http://www.securityfocus.com/bid/7837"},{"name":"4933","refsource":"OSVDB","url":"http://www.osvdb.org/4933"},{"name":"8979","refsource":"SECUNIA","url":"http://secunia.com/advisories/8979"},{"name":"20030606 Critical Vulnerabilities In Max Web Portal","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1212","datePublished":"2005-05-19T04:00:00.000Z","dateReserved":"2005-05-19T00:00:00.000Z","dateUpdated":"2024-08-08T02:19:45.940Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:maxwebportal:maxwebportal:1.30:*:*:*:*:*:*:*","matchCriteriaId":"B22E55F5-AA5E-4F68-ACC2-F170D811FA08"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1212","Ordinal":"1","Title":"CVE-2003-1212","CVE":"CVE-2003-1212","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1212","Ordinal":"1","NoteData":"MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.","Type":"Description","Title":"CVE-2003-1212"},{"CveYear":"2003","CveId":"1212","Ordinal":"2","NoteData":"2005-05-19","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1212","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}