{"api_version":"1","generated_at":"2026-07-23T06:34:10+00:00","cve":"CVE-2003-1553","urls":{"html":"https://cve.report/CVE-2003-1553","api":"https://cve.report/api/cve/CVE-2003-1553.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1553","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1553"},"summary":{"title":"CVE-2003-1553","description":"Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://securityreason.com/securityalert/3780","name":"http://securityreason.com/securityalert/3780","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SIPS (PHP) - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7134","name":"http://www.securityfocus.com/bid/7134","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SIPS User Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/315504/30/25460/threaded","name":"http://www.securityfocus.com/archive/1/315504/30/25460/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11572","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1553","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1553","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1553","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sips","cpe5":"sips","cpe6":"0.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2003-1553","qid":"730061","title":"SIPS User Information Disclosure Vulnerability"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:35:16.441Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"sips-user-obtain-information(11572)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11572"},{"name":"3780","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3780"},{"name":"20030318 SIPS (PHP)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/315504/30/25460/threaded"},{"name":"7134","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7134"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-03-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"sips-user-obtain-information(11572)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11572"},{"name":"3780","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3780"},{"name":"20030318 SIPS (PHP)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/315504/30/25460/threaded"},{"name":"7134","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7134"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1553","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"sips-user-obtain-information(11572)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11572"},{"name":"3780","refsource":"SREASON","url":"http://securityreason.com/securityalert/3780"},{"name":"20030318 SIPS (PHP)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/315504/30/25460/threaded"},{"name":"7134","refsource":"BID","url":"http://www.securityfocus.com/bid/7134"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1553","datePublished":"2008-03-26T17:00:00.000Z","dateReserved":"2008-03-26T00:00:00.000Z","dateUpdated":"2024-08-08T02:35:16.441Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sips:sips:0.2.2:*:*:*:*:*:*:*","matchCriteriaId":"263CC1D9-EF68-4BCF-9724-A41AD981193C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1553","Ordinal":"1","Title":"CVE-2003-1553","CVE":"CVE-2003-1553","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1553","Ordinal":"1","NoteData":"Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.","Type":"Description","Title":"CVE-2003-1553"},{"CveYear":"2003","CveId":"1553","Ordinal":"2","NoteData":"2008-03-26","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1553","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}