Vulnerabilities (CVE)

Filtered by vendor Andy Prevost Subscribe
Filtered by product Ttcms
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0320 1 Andy Prevost 1 Ttcms 2024-02-04 7.5 HIGH N/A
header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.