Back

CVE-2003-1406

PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (3)

Vendor Product Version
adalis_infomatique d_forum 1.0
adalis_infomatique d_forum 1.10
adalis_infomatique d_forum 1.11

GitHub Security Advisory GHSA-5366-ff25-5h7f

PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.53%

Top 16% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub