CVE Vulnerabilities

CVE-2002-0614

Published: Jun 18, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server.

Affected Software

NameVendorStart VersionEnd Version
Php-surveyPhp-survey2000-04-20 (including)2000-04-20 (including)
Php-surveyPhp-survey2000-04-21 (including)2000-04-21 (including)
Php-surveyPhp-survey2000-06-14 (including)2000-06-14 (including)
Php-surveyPhp-survey2000-06-14b (including)2000-06-14b (including)
Php-surveyPhp-survey2000-06-15 (including)2000-06-15 (including)
Php-surveyPhp-surveyprebeta2000-03-27 (including)prebeta2000-03-27 (including)

References