CVE-2003-1550 is an information disclosure vulnerability affecting XOOPS 2.0 and potentially earlier versions. It allows remote attackers to reveal the installation path of the XOOPS application through error messages generated by an invalid xoopsOption parameter. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and allows for unauthorized information disclosure without requiring authentication or complex attack methods. While there is no evidence of active exploitation, exploit code exists on ExploitDB, and the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0CPE matchmatch criteria | cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.