Vulnerability Description
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpwebsite | Phpwebsite | 0.8.2 |
References
- http://marc.info/?l=bugtraq&m=103279980906880&w=2
- http://phpwebsite.appstate.edu/article.php?sid=400Vendor Advisory
- http://www.iss.net/security_center/static/10164.php
- http://www.osvdb.org/3848
- http://www.securityfocus.com/bid/5779
- http://marc.info/?l=bugtraq&m=103279980906880&w=2
- http://phpwebsite.appstate.edu/article.php?sid=400Vendor Advisory
- http://www.iss.net/security_center/static/10164.php
- http://www.osvdb.org/3848
- http://www.securityfocus.com/bid/5779
FAQ
What is CVE-2002-1135?
CVE-2002-1135 is a vulnerability with a CVSS score of 7.5 (HIGH). modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.
How severe is CVE-2002-1135?
CVE-2002-1135 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1135?
Check the references section above for vendor advisories and patch information. Affected products include: Phpwebsite Phpwebsite.