CVE-2002-1660: OS Command Injection
Published Dec 31, 2002
·Updated
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
Affected Software
1 affected component
Jelsoft vBulletin<=2.1.9
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1660?
CVE-2002-1660 is classified as a high severity vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2002-1660?
To fix CVE-2002-1660, upgrade vBulletin to version 2.2.0 or later.
3
What systems are affected by CVE-2002-1660?
CVE-2002-1660 affects vBulletin versions prior to 2.2.0.
4
Can CVE-2002-1660 be exploited remotely?
Yes, CVE-2002-1660 can be exploited remotely by attackers sending crafted requests to the vulnerable application.
5
What impact does CVE-2002-1660 have on my system?
CVE-2002-1660 allows attackers to execute arbitrary commands on the server, potentially compromising the entire system.