Vulnerability Name: | CVE-2001-1370 (CCN-6892) | ||||||||
Assigned: | 2001-07-21 | ||||||||
Published: | 2001-07-21 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2001-027.0 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2001-027.0 Linux - Security problems in imp Source: CCN Type: BugTraq Mailing List, Sat Jul 21 2001 - 17:22:22 CDT IMP 2.2.6 (SECURITY) released Source: CCN Type: BugTraq Mailing List, Sun Jul 22 2001 - 08:24:24 CDT Re: IMP 2.2.6 (SECURITY) released Source: CCN Type: BugTraq Mailing List, Sun Jul 22 2001 - 22:04:20 CDT [SEC] Hole in PHPLib 7.2 prepend.php3 Source: CCN Type: Trustix Secure Linux Security Advisory TSLSA-2001-0014 PHPLib Source: MITRE Type: CNA CVE-2001-1370 Source: CONECTIVA Type: UNKNOWN CLA-2001:410 Source: CCN Type: Conectiva Linux Announcement CLSA-2001:410 Remote vulnerability affects the IMP webmail system Source: BUGTRAQ Type: UNKNOWN 20010726 TSLSA-2001-0014 - PHPLib Source: BUGTRAQ Type: UNKNOWN 20010721 IMP 2.2.6 (SECURITY) released Source: DEBIAN Type: Patch, Vendor Advisory DSA-073 Source: DEBIAN Type: DSA-073 imp -- 3 remote exploits Source: CCN Type: Horde Web site Latest News on 2001-07-21 Source: XF Type: Vendor Advisory phplib-script-execution(6892) Source: CCN Type: OSVDB ID: 5411 PHPLib prepend.php3 Remote Script Execution Source: BUGTRAQ Type: Vendor Advisory 20010722 [SEC] Hole in PHPLib 7.2 prepend.php3 Source: BID Type: Exploit, Patch, Vendor Advisory 3079 Source: CCN Type: BID-3079 Multiple Vendor PHPLIB Remote Script Execution Vulnerability Source: XF Type: UNKNOWN phplib-script-execution(6892) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |