5
CVSSv2

CVE-2002-2134

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

haut.php in PEEL 1.0b allows remote malicious users to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file.

Vulnerable Product Search on Vulmon Subscribe to Product

peel peel 1.0b

Exploits

source: wwwsecurityfocuscom/bid/6496/info PEEL is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers An attacker may exploit this by supplying a path to a maliciously created file, located on an attacker-controlled host as a value for some parameters If the remote file is a PHP scri ...