CVE-2002-1211: High severity Jason Orcutt Prometheus vulnerability
Published Nov 12, 2002
·Updated
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUSLIBRARYBASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test.php scripts.
Affected Software
3 affected components
Jason Orcutt Prometheus=3.0_beta
Jason Orcutt Prometheus=4.0_beta
Jason Orcutt Prometheus=6.0
Remediation
Patch Available
Event History
Nov 12, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1211?
CVE-2002-1211 has a critical severity due to its ability to allow remote code execution.
2
How do I fix CVE-2002-1211?
To fix CVE-2002-1211, upgrade Prometheus to version 6.0 or later where the vulnerability is resolved.
3
Which versions are affected by CVE-2002-1211?
CVE-2002-1211 affects Prometheus versions 6.0 and earlier.
4
What type of attack does CVE-2002-1211 enable?
CVE-2002-1211 enables remote attackers to execute arbitrary PHP code.
5
What components are vulnerable in CVE-2002-1211?
The components vulnerable in CVE-2002-1211 include index.php, install.php, and various test_*.php scripts.