CVE-2002-1135: High severity phpwebsite phpwebsite vulnerability
Published Oct 4, 2002
·Updated
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an incprefix parameter that points to the malicious code.
Affected Software
1 affected component
phpWebSite phpWebSite=0.8.2
Event History
Oct 4, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1135?
CVE-2002-1135 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2002-1135?
To fix CVE-2002-1135, upgrade to a version of phpWebSite that is later than 0.8.2, which addresses this vulnerability.
3
Who is affected by CVE-2002-1135?
CVE-2002-1135 affects users of phpWebSite versions 0.8.2 and earlier.
4
What kind of attacks can be executed due to CVE-2002-1135?
Attackers can execute arbitrary PHP source code by exploiting the inc_prefix parameter in vulnerable versions of phpWebSite.
5
Is CVE-2002-1135 still a concern today?
While this specific vulnerability is older, it still serves as a reminder to maintain updated software to avoid similar risks.