Vulnerability Name:

CVE-2001-1370 (CCN-6892)

Assigned:2001-07-21
Published:2001-07-21
Updated:2016-10-18
Summary:prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CALDERA
Type: UNKNOWN
CSSA-2001-027.0

Source: CCN
Type: Caldera International, Inc. Security Advisory CSSA-2001-027.0
Linux - Security problems in imp

Source: CCN
Type: BugTraq Mailing List, Sat Jul 21 2001 - 17:22:22 CDT
IMP 2.2.6 (SECURITY) released

Source: CCN
Type: BugTraq Mailing List, Sun Jul 22 2001 - 08:24:24 CDT
Re: IMP 2.2.6 (SECURITY) released

Source: CCN
Type: BugTraq Mailing List, Sun Jul 22 2001 - 22:04:20 CDT
[SEC] Hole in PHPLib 7.2 prepend.php3

Source: CCN
Type: Trustix Secure Linux Security Advisory TSLSA-2001-0014
PHPLib

Source: MITRE
Type: CNA
CVE-2001-1370

Source: CONECTIVA
Type: UNKNOWN
CLA-2001:410

Source: CCN
Type: Conectiva Linux Announcement CLSA-2001:410
Remote vulnerability affects the IMP webmail system

Source: BUGTRAQ
Type: UNKNOWN
20010726 TSLSA-2001-0014 - PHPLib

Source: BUGTRAQ
Type: UNKNOWN
20010721 IMP 2.2.6 (SECURITY) released

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-073

Source: DEBIAN
Type: DSA-073
imp -- 3 remote exploits

Source: CCN
Type: Horde Web site
Latest News on 2001-07-21

Source: XF
Type: Vendor Advisory
phplib-script-execution(6892)

Source: CCN
Type: OSVDB ID: 5411
PHPLib prepend.php3 Remote Script Execution

Source: BUGTRAQ
Type: Vendor Advisory
20010722 [SEC] Hole in PHPLib 7.2 prepend.php3

Source: BID
Type: Exploit, Patch, Vendor Advisory
3079

Source: CCN
Type: BID-3079
Multiple Vendor PHPLIB Remote Script Execution Vulnerability

Source: XF
Type: UNKNOWN
phplib-script-execution(6892)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:phplib_team:phplib:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:phplib_team:phplib:7.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:phplib_team:phplib:7.2b:*:*:*:*:*:*:*
  • OR cpe:/a:phplib_team:phplib:7.2c:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:trustix:secure_linux:1.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:1.01:*:*:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:1.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:4.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:4.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:5.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde:1.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:horde:imp:2.2.5:*:*:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:1.5:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:73
    V
    3 remote exploits
    2001-08-11
    BACK
    phplib_team phplib 7.2
    phplib_team phplib 7.2.1
    phplib_team phplib 7.2b
    phplib_team phplib 7.2c
    trustix secure linux 1.1
    conectiva linux 6.0
    trustix secure linux 1.01
    trustix secure linux 1.2
    conectiva linux 4.1
    conectiva linux 4.2
    conectiva linux 5.0
    conectiva linux 5.1
    conectiva linux 7.0
    horde horde 1.2.5
    horde imp 2.2.5
    trustix secure linux 1.5
    debian debian linux 2.2