Back

CVE-2003-1402

PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-20

CVSS Metrics

Affected Products (2)

Vendor Product Version
kietu kietu 2.0
kietu kietu 2.3

GitHub Security Advisory GHSA-rvfv-82qg-gr7m

PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.56%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub