7.5

CVE-2002-1757

Exploit
PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phprojekt ≫ Phprojekt Version 2.0
Phprojekt ≫ Phprojekt Version 2.0.1
Phprojekt ≫ Phprojekt Version 2.1
Phprojekt ≫ Phprojekt Version 2.1a
Phprojekt ≫ Phprojekt Version 2.2
Phprojekt ≫ Phprojekt Version 2.3
Phprojekt ≫ Phprojekt Version 2.4
Phprojekt ≫ Phprojekt Version 2.4a
Phprojekt ≫ Phprojekt Version 3.0
Phprojekt ≫ Phprojekt Version 3.1
Phprojekt ≫ Phprojekt Version 3.1a
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.14% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://online.securityfocus.com/archive/1/269407
http://www.securityfocus.com/bid/4596
Patch
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/8943