prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phplib | Phplib_team | 7.2 (including) | 7.2 (including) |
Phplib | Phplib_team | 7.2.1 (including) | 7.2.1 (including) |
Phplib | Phplib_team | 7.2b (including) | 7.2b (including) |
Phplib | Phplib_team | 7.2c (including) | 7.2c (including) |