Back

CVE-2004-1592

PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
ocportal ocportal 1.0.3

GitHub Security Advisory GHSA-jw79-gm26-2pgj

PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.05%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub