Vulnerability Description
globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCookie parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php Address | Php Address | 0.2e |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0182.html
- http://online.securityfocus.com/archive/1/277987
- http://www.iss.net/security_center/static/9379.phpExploit
- http://www.securityfocus.com/bid/5039ExploitPatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0182.html
- http://online.securityfocus.com/archive/1/277987
- http://www.iss.net/security_center/static/9379.phpExploit
- http://www.securityfocus.com/bid/5039ExploitPatchVendor Advisory
FAQ
What is CVE-2002-0953?
CVE-2002-0953 is a vulnerability with a CVSS score of 7.5 (HIGH). globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCook...
How severe is CVE-2002-0953?
CVE-2002-0953 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0953?
Check the references section above for vendor advisories and patch information. Affected products include: Php Address Php Address.