VulnerabilityModified
CVE-2002-2200
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php.
HIGH 7.5EPSS 7.12%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.12% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- benjamin lefevre/dobermann forum
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.