7.5
CVSSv2

CVE-2002-1481

Published: 22/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

savesettings.php in phpGB 1.20 and previous versions does not require authentication, which allows remote malicious users to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgb phpgb 1.10

phpgb phpgb 1.20

Exploits

source: wwwsecurityfocuscom/bid/5679/info phpGB is subject to a PHP code injection vulnerability After bypassing authentication it is possible to inject code into the guestbook configuration file (configphp) by supplying malicious parameters for the savesettingsphp script The configuration file is referenced in most of the other gues ...