CVE Vulnerabilities

CVE-2002-1757

Published: Dec 31, 2002 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with sms in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using mail_send.php/sms.

Affected Software

Name Vendor Start Version End Version
Phprojekt Phprojekt 2.0 (including) 2.0 (including)
Phprojekt Phprojekt 2.0.1 (including) 2.0.1 (including)
Phprojekt Phprojekt 2.1 (including) 2.1 (including)
Phprojekt Phprojekt 2.1a (including) 2.1a (including)
Phprojekt Phprojekt 2.2 (including) 2.2 (including)
Phprojekt Phprojekt 2.3 (including) 2.3 (including)
Phprojekt Phprojekt 2.4 (including) 2.4 (including)
Phprojekt Phprojekt 2.4a (including) 2.4a (including)
Phprojekt Phprojekt 3.0 (including) 3.0 (including)
Phprojekt Phprojekt 3.1 (including) 3.1 (including)
Phprojekt Phprojekt 3.1a (including) 3.1a (including)

References