CVE-2001-1370
HIGH 10.0EPSS 17.2%
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 17.20% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2003-04-02
- Updated
- 2024-08-08