PT-2003-1199 · Organicphp · Organicphp Php-Affiliate

Published

2003-03-18

·

Updated

2008-09-05

·

CVE-2002-1462

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OrganicPHP PHP-affiliate version 1.0
Description The issue allows remote attackers to modify information of other users by altering certain hidden form fields in the details2.php file.
Recommendations For OrganicPHP PHP-affiliate version 1.0, consider restricting access to the details2.php file until a patch is available, and avoid using hidden form fields that can be modified by remote attackers.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1462

Affected Products

Organicphp Php-Affiliate