# CVE-2003-0770

## Summary

- **CVE ID:** CVE-2003-0770
- **Severity:** UNKNOWN
- **CVSS Score:** 0.44
- **CWE:** N/A
- **Published:** Sep 12, 2003
- **Last Modified:** Mar 16, 2026

## Description

FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://marc.info/?l=bugtraq&m=106381136115972&w=2)
- [CNA](http://www.securityfocus.com/archive/1/336598)
- [CNA](http://www.securityfocus.com/archive/1/317234)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 10.91%
- **EPSS Percentile:** 93.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._