CVE-2002-1726
secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- brokenbytes/photodb
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/82/270970
- http://www.ifrance.com/kitetoua/tuto/5holes4.txtVendor Advisory
- http://www.securityfocus.com/bid/4669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9002
- http://online.securityfocus.com/archive/82/270970
- http://www.ifrance.com/kitetoua/tuto/5holes4.txtVendor Advisory
- http://www.securityfocus.com/bid/4669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9002
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.