CVE-2005-1787
high · 7.5setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.
7.5
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2005-05-27
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| phpstat | phpstat | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=111721290726958&w=2
- http://secunia.com/advisories/15516
- http://securitytracker.com/id?1014064
- http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt
- http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt
- http://marc.info/?l=bugtraq&m=111721290726958&w=2
- http://secunia.com/advisories/15516
- http://securitytracker.com/id?1014064
- http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt
- http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2005-1787