CVE Vulnerabilities

CVE-2002-1481

Published: Apr 22, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.

Affected Software

Name Vendor Start Version End Version
Phpgb Phpgb 1.10 (including) 1.10 (including)
Phpgb Phpgb 1.20 (including) 1.20 (including)

References