CVE Vulnerabilities

CVE-2001-1370

Published: Jul 21, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.

Affected Software

NameVendorStart VersionEnd Version
PhplibPhplib_team7.2 (including)7.2 (including)
PhplibPhplib_team7.2.1 (including)7.2.1 (including)
PhplibPhplib_team7.2b (including)7.2b (including)
PhplibPhplib_team7.2c (including)7.2c (including)

References