CVE-2003-1425

CRITICAL ⚠ Exploit

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

Affects 1 product across 1 vendor.

BCS8.76
CVSS 2.010.0
EPSS11.5%
Percentile96th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in cPanel 5.0's guestbook.cgi script allows remote attackers to execute arbitrary commands through the template parameter, posing a severe risk to system integrity and security.

BSID: BS-2003-GLOBAL-196486-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2003-1425?
A critical vulnerability in cPanel 5.0's guestbook.cgi script allows remote attackers to execute arbitrary commands through the template parameter, posing a severe risk to system integrity and security.
What is the CVSS score for CVE-2003-1425?
CVE-2003-1425 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 11.5%.
Is CVE-2003-1425 actively exploited?
Public exploit available for CVE-2003-1425. Exploitation risk elevated.
How do I remediate CVE-2003-1425?
Priority: IMMEDIATE.
What systems are affected by CVE-2003-1425?
CVE-2003-1425 affects: Cpanel.
Vulnerability Details
CVE IDCVE-2003-1425
BSIDBS-2003-GLOBAL-196486-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2003-12-31
Last Modified2026-04-16
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by sending a maliciously crafted request to the guestbook.cgi script with a specially designed template parameter. This parameter can be used to inject and execute arbitrary commands on the server.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cpanel Cpanel
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8252 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Cpanel
CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-2004-1769 10.0 The "Allow cPanel users to reset their password via email" feature in cPanel ... CVE-2004-1770 10.0 The login page for cPanel 9.1.0, and possibly other versions, allows remote a... CVE-2024-8767 9.9 Sensitive data disclosure and manipulation due to unnecessary privileges assi... CVE-2016-10817 9.8 cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch l...
View all Cpanel CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →