AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2003-1426

LOW · CVSS 3.3 EPSS 0.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2003-12-31 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2003-1426
Severity
LOW
CVSS
3.3
EPSS
0.46%

Original Filing — NVD Description

Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.