PT-2001-2369 · Phormation · Phormation Php Script

Published

2001-10-02

·

Updated

2008-09-10

·

CVE-2001-1237

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Phormation PHP script versions 0.9.1 and earlier
Description The issue allows remote attackers to execute arbitrary code by including files from remote web sites. This is achieved by using an HTTP request that modifies the phormationdir variable.
Recommendations For Phormation PHP script versions 0.9.1 and earlier, consider restricting access to the phormationdir variable to prevent modification via HTTP requests until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1237

Affected Products

Phormation Php Script