CVE-2002-2045
N/A
N/A
Summary
x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://seclists.org/lists/vuln-dev/2002/Mar/0156.html
- http://www.securityfocus.com/bid/4279
- http://www.securityfocus.com/bid/4280
- http://securitytracker.com/id?1003827
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8467
- http://www.ifrance.com/kitetoua/tuto/x_holes.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8466
References
- http://seclists.org/lists/vuln-dev/2002/Mar/0156.html
- http://www.securityfocus.com/bid/4279
- http://www.securityfocus.com/bid/4280
- http://securitytracker.com/id?1003827
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8467
- http://www.ifrance.com/kitetoua/tuto/x_holes.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8466
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.