CVE-2002-1149
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.
El procedimiento de instalación en Invision Board sugiere que los usuarios instalen el programa phpinfo.php en la raíz del web, lo que filtra información sensible como nombres de rutas, información del SO, y configuración de php.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2002-09-24 CVE Reserved
- 2002-10-01 CVE Published
- 2024-08-08 CVE Updated
- 2024-08-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=103290602609197&w=2 | Mailing List | |
http://www.osvdb.org/3356 | Vdb Entry | |
http://www.securityfocus.com/bid/5789 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.iss.net/security_center/static/10178.php | 2016-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Invision Power Services Search vendor "Invision Power Services" | Invision Board Search vendor "Invision Power Services" for product "Invision Board" | 1.0 Search vendor "Invision Power Services" for product "Invision Board" and version "1.0" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Board Search vendor "Invision Power Services" for product "Invision Board" | 1.0.1 Search vendor "Invision Power Services" for product "Invision Board" and version "1.0.1" | - |
Affected
|