Back

CVE-2003-1253

PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
sangwan_kim bookmark4u 1.8.3

GitHub Security Advisory GHSA-fhvp-97rr-x9r8

PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.44%

Top 29% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub