{"api_version":"1","generated_at":"2026-07-23T05:39:47+00:00","cve":"CVE-2003-1298","urls":{"html":"https://cve.report/CVE-2003-1298","api":"https://cve.report/api/cve/CVE-2003-1298.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1298","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1298"},"summary":{"title":"CVE-2003-1298","description":"Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with \"./..\" (dot slash dot dot).","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25396","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25396","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152","name":"http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://secunia.com/advisories/19359","name":"http://secunia.com/advisories/19359","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"AnyPortal(php) \"F\" Directory Traversal Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17197","name":"http://www.securityfocus.com/bid/17197","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/23984","name":"http://www.osvdb.org/23984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/1053","name":"http://www.vupen.com/english/advisories/2006/1053","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1298","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1298","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1298","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anyportal_php","cpe5":"anyportal_php","cpe6":"0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:19:46.183Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19359","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19359"},{"name":"ADV-2006-1053","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1053"},{"name":"17197","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17197"},{"name":"anyportalphp-siteman-directory-traversal(25396)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25396"},{"name":"23984","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23984"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with \"./..\" (dot slash dot dot)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19359","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19359"},{"name":"ADV-2006-1053","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1053"},{"name":"17197","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17197"},{"name":"anyportalphp-siteman-directory-traversal(25396)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25396"},{"name":"23984","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23984"},{"tags":["x_refsource_MISC"],"url":"http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1298","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with \"./..\" (dot slash dot dot)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19359","refsource":"SECUNIA","url":"http://secunia.com/advisories/19359"},{"name":"ADV-2006-1053","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1053"},{"name":"17197","refsource":"BID","url":"http://www.securityfocus.com/bid/17197"},{"name":"anyportalphp-siteman-directory-traversal(25396)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25396"},{"name":"23984","refsource":"OSVDB","url":"http://www.osvdb.org/23984"},{"name":"http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152","refsource":"MISC","url":"http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1298","datePublished":"2006-03-23T11:00:00.000Z","dateReserved":"2006-03-23T00:00:00.000Z","dateUpdated":"2024-08-08T02:19:46.183Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:anyportal_php:anyportal_php:0.1:*:*:*:*:*:*:*","matchCriteriaId":"BEA1D649-A40D-4841-85D3-D458B18B7890"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1298","Ordinal":"1","Title":"CVE-2003-1298","CVE":"CVE-2003-1298","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1298","Ordinal":"1","NoteData":"Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with \"./..\" (dot slash dot dot).","Type":"Description","Title":"CVE-2003-1298"},{"CveYear":"2003","CveId":"1298","Ordinal":"2","NoteData":"2006-03-23","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1298","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}