VulnerabilityModified
CVE-2004-2602
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.
MEDIUM 6.8EPSS 1.93%
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- ubertec/help center live
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/13652Vendor Advisory
- http://securitytracker.com/id?1012685Exploit
- http://www.gulftech.org/?node=research&article_id=00058-12242004Exploit
- http://www.osvdb.org/12598Exploit
- http://www.securityfocus.com/bid/12105Exploit
- http://www.ubertec.co.uk/forums/showthread/php?t=2376Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18694
- http://secunia.com/advisories/13652Vendor Advisory
- http://securitytracker.com/id?1012685Exploit
- http://www.gulftech.org/?node=research&article_id=00058-12242004Exploit
- http://www.osvdb.org/12598Exploit
- http://www.securityfocus.com/bid/12105Exploit
- http://www.ubertec.co.uk/forums/showthread/php?t=2376Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18694
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.