CVE-2007-2985
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.17% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- pheap/pheap
- Source
- cve@mitre.org
References
- http://osvdb.org/36737
- http://secunia.com/advisories/25460Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34592
- https://www.exploit-db.com/exploits/4006
- http://osvdb.org/36737
- http://secunia.com/advisories/25460Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34592
- https://www.exploit-db.com/exploits/4006
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.