CVE-2002-2335

Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:john_drake:killer_protection:1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/294208 - () http://online.securityfocus.com/archive/1/294208 -
References () http://www.iss.net/security_center/static/10315.php - () http://www.iss.net/security_center/static/10315.php -
References () http://www.securityfocus.com/bid/5905 - () http://www.securityfocus.com/bid/5905 -

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2335

Mitre link : CVE-2002-2335

CVE.ORG link : CVE-2002-2335


JSON object : View

Products Affected

john_drake

  • killer_protection
CWE
CWE-16

Configuration