First published: Tue Dec 31 2002(Updated: )
phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Phpsquidpass |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2175 is considered a moderate severity vulnerability due to its potential to allow remote authenticated attackers to manipulate usernames.
To fix CVE-2002-2175, upgrade to a version of phpSquidPass that is 0.2 or later, where the regular expression issue has been resolved.
CVE-2002-2175 is a security vulnerability that involves improper user authentication due to a flawed regular expression.
Users of phpSquidPass versions prior to 0.2 are affected by CVE-2002-2175 and should take immediate action to prevent exploitation.
CVE-2002-2175 can lead to unauthorized deletion of usernames, potentially disrupting user access and compromising account integrity.