← All CVEs

CVE-2001-1370

high · 10

prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.

10
CVSS
17.2%
EPSS (exploit prob.)
97th
EPSS percentile
2001-07-21
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
phplib_teamphplib7.2
phplib_teamphplib7.2.1
phplib_teamphplib7.2b
phplib_teamphplib7.2c

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2001-1370