CVE Vulnerabilities

CVE-2002-0267

Published: May 29, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the theme field followed by the Status::admin command, which causes the Status line to be entered into the password file.

Affected Software

NameVendorStart VersionEnd Version
SipsSips0.2.4 (including)0.2.4 (including)
SipsSips0.3.0 (including)0.3.0 (including)
SipsSips0.3.0pl1 (including)0.3.0pl1 (including)
SipsSips0.3.0pl2 (including)0.3.0pl2 (including)

References