10

CVE-2001-1370

Exploit
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phplib TeamPhplib Version7.2
Phplib TeamPhplib Version7.2.1
Phplib TeamPhplib Version7.2b
Phplib TeamPhplib Version7.2c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.2% 0.967
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000410
http://online.securityfocus.com/archive/1/198495
http://www.debian.org/security/2001/dsa-073
Patch
Vendor Advisory
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-027.0.txt
http://marc.info/?l=bugtraq&m=99616122712122&w=2
http://www.iss.net/security_center/static/6892.php
Vendor Advisory
http://www.securityfocus.com/archive/1/198768
Vendor Advisory
http://www.securityfocus.com/bid/3079
Patch
Vendor Advisory
Exploit