Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html | |
http://www.iss.net/security_center/static/7215.php | |
http://www.kb.cert.org/vuls/id/847803 | US Government Resource |
http://www.peaceworks.ca/phormation/phormation-0.9.2.tar.gz | |
http://www.securityfocus.com/bid/3393 | Exploit Patch Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html | |
http://www.iss.net/security_center/static/7215.php | |
http://www.kb.cert.org/vuls/id/847803 | US Government Resource |
http://www.peaceworks.ca/phormation/phormation-0.9.2.tar.gz | |
http://www.securityfocus.com/bid/3393 | Exploit Patch Vendor Advisory |
Configurations
History
20 Nov 2024, 23:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html - | |
References | () http://www.iss.net/security_center/static/7215.php - | |
References | () http://www.kb.cert.org/vuls/id/847803 - US Government Resource | |
References | () http://www.peaceworks.ca/phormation/phormation-0.9.2.tar.gz - | |
References | () http://www.securityfocus.com/bid/3393 - Exploit, Patch, Vendor Advisory |
Information
Published : 2001-10-02 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2001-1237
Mitre link : CVE-2001-1237
CVE.ORG link : CVE-2001-1237
JSON object : View
Products Affected
peaceworks_computer_consulting
- phormation
CWE