Back

CVE-2004-1403

PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (10)

Vendor Product Version
sir gnuboard 3.30
sir gnuboard 3.31
sir gnuboard 3.32
sir gnuboard 3.33
sir gnuboard 3.34
sir gnuboard 3.35
sir gnuboard 3.36
sir gnuboard 3.37
sir gnuboard 3.38
sir gnuboard 3.39

GitHub Security Advisory GHSA-gqw2-jg2j-9fpj

PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.71%

Top 25% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub