CVE-2002-1726

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:brokenbytes:photodb:1.4:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/82/270970 - () http://online.securityfocus.com/archive/82/270970 -
References () http://www.ifrance.com/kitetoua/tuto/5holes4.txt - Vendor Advisory () http://www.ifrance.com/kitetoua/tuto/5holes4.txt - Vendor Advisory
References () http://www.securityfocus.com/bid/4669 - () http://www.securityfocus.com/bid/4669 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/9002 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/9002 -

Information

Published : 2002-12-31 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2002-1726

Mitre link : CVE-2002-1726

CVE.ORG link : CVE-2002-1726


JSON object : View

Products Affected

brokenbytes

  • photodb