First published: Mon Aug 12 2002(Updated: )
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program stored on a remote server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
B2evolution | =0.6_pre |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0734 has a critical severity level due to the potential for remote code execution.
To fix CVE-2002-0734, upgrade to a version of B2 that is newer than 2.0.6pre2.
CVE-2002-0734 affects B2 version 2.0.6pre2 and earlier.
Attackers can execute arbitrary PHP code on the server due to improper loading of the b2config.php file.
CVE-2002-0734 is a remote vulnerability, allowing attackers to exploit it over the network.