PoC Index

CVE-2001-1370

HIGH 10.0EPSS 17.2%

prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
17.20% chance of exploitation in the next 30 days, 97th percentile
Published
2003-04-02
Updated
2024-08-08

ExploitDB entries (1)

References

Related