CVE-2004-1448 describes a vulnerability in Jetbox One CMS, specifically version 2.0.8 and potentially others, where remote attackers with Author privileges can upload and execute arbitrary PHP files within the IMAGES module. This allows for arbitrary code execution, leading to potential compromise of confidentiality, integrity, and availability. While the CVSS score is 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P), indicating local access and low attack complexity, the EPSS score is low, suggesting a low probability of exploitation. There is no known active exploitation, publicly available exploit code in Metasploit, Nuclei, or ExploitDB, and it is not listed on the KEV catalog, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.8CPE matchmatch criteria | cpe:2.3:a:jetbox:jetbox_one_cms:2.0.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.