AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2003-1340

MEDIUM · CVSS 6.5 EPSS 0.95%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2003-12-31 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Cisco. It may be remotely exploitable. It involves a SQL injection risk. Exploitation may require the attacker to be authenticated.

CVE
CVE-2003-1340
Severity
MEDIUM
CVSS
6.5
EPSS
0.95%
Cisco

Original NVD Description

Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.