CVE-2002-1435: High severity Achievo Achievo vulnerability
Published Apr 11, 2003
·Updated
class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allowurlfopen' setting is enabled via a URL in the configatkroot parameter that points to the code.
Affected Software
10 affected components
Achievo Achievo=0.7.1
Achievo Achievo=0.8.0_rc1
Achievo Achievo=0.8.0
Achievo Achievo=0.8.1
Achievo Achievo=0.8.0_rc2
Achievo Achievo=0.7.2
Achievo Achievo=0.9.1
Achievo Achievo=0.7.3
Achievo Achievo=0.9.0
Achievo Achievo=0.7.0
Remediation
Patch Available
Patch Available
Event History
Apr 11, 2003
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1435?
CVE-2002-1435 has a high severity rating as it allows remote code execution, potentially compromising the affected systems.
2
How do I fix CVE-2002-1435?
To fix CVE-2002-1435, disable the 'allow_url_fopen' setting in the PHP configuration file.
3
Which versions of Achievo are affected by CVE-2002-1435?
CVE-2002-1435 affects Achievo versions 0.7.0 to 0.9.1, except for 0.8.2.
4
What kind of attacks can CVE-2002-1435 allow?
CVE-2002-1435 allows remote attackers to execute arbitrary PHP code on the server.
5
Is there a patch available for CVE-2002-1435?
There is no specific patch mentioned for CVE-2002-1435; the recommended action is to disable 'allow_url_fopen'.