CVE-2002-2289: Infoleak
Published Dec 31, 2002
·Updated
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
Affected Software
1 affected component
Working Resources Inc. BadBlue=1.7.1
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 18, 2007
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2289?
CVE-2002-2289 has a moderate severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2002-2289?
To fix CVE-2002-2289, users should upgrade BadBlue to a version that eliminates the phpinfo function call in soinfo.php.
3
What kind of information does CVE-2002-2289 expose?
CVE-2002-2289 exposes sensitive information including ODBC passwords due to the improper use of the phpinfo function.
4
Who is affected by CVE-2002-2289?
CVE-2002-2289 affects users running BadBlue version 1.7.1.
5
What is the impact of CVE-2002-2289?
The impact of CVE-2002-2289 is that it allows remote attackers to access sensitive system information.