6.4
CVE-2002-2045
- EPSS 1.71%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:00:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.71% | 0.744 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://www.ifrance.com/kitetoua/tuto/x_holes.txt
http://seclists.org/lists/vuln-dev/2002/Mar/0156.html
http://securitytracker.com/id?1003827
http://www.securityfocus.com/bid/4279
http://www.securityfocus.com/bid/4280
https://exchange.xforce.ibmcloud.com/vulnerabilities/8466
https://exchange.xforce.ibmcloud.com/vulnerabilities/8467