CVE Vulnerabilities

CVE-2002-1435

Published: Apr 11, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the allow_url_fopen setting is enabled via a URL in the config_atkroot parameter that points to the code.

Affected Software

Name Vendor Start Version End Version
Achievo Achievo 0.7.0 (including) 0.7.0 (including)
Achievo Achievo 0.7.1 (including) 0.7.1 (including)
Achievo Achievo 0.7.2 (including) 0.7.2 (including)
Achievo Achievo 0.7.3 (including) 0.7.3 (including)
Achievo Achievo 0.8.0 (including) 0.8.0 (including)
Achievo Achievo 0.8.0_rc1 (including) 0.8.0_rc1 (including)
Achievo Achievo 0.8.0_rc2 (including) 0.8.0_rc2 (including)
Achievo Achievo 0.8.1 (including) 0.8.1 (including)
Achievo Achievo 0.9.0 (including) 0.9.0 (including)
Achievo Achievo 0.9.1 (including) 0.9.1 (including)

References