7.5
CVSSv2

CVE-2002-1435

Published: 11/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

class.atkdateattribute.js.php in Achievo 0.7.0 up to and including 0.9.1, except 0.8.2, allows remote malicious users to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config_atkroot parameter that points to the code.

Vulnerable Product Search on Vulmon Subscribe to Product

achievo achievo 0.9.0

achievo achievo 0.9.1

achievo achievo 0.8.0_rc1

achievo achievo 0.8.1

achievo achievo 0.7.0

achievo achievo 0.7.1

achievo achievo 0.7.2

achievo achievo 0.7.3

achievo achievo 0.8.0

achievo achievo 0.8.0_rc2

Exploits

source: wwwsecurityfocuscom/bid/5552/info Achievo includes a PHP script which is used to generate JavaScript (classatkdateattributejsphp) This script employs a number of PHP include_once() statements to call code contained in function libraries and grab configuration information Attackers may subvert the variable ($config_atkroot) wh ...