CVE-2002-0614
Published Jun 18, 2002
Last updated 16 years ago
Overview
- Description
- PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:php-survey:php-survey:2000-04-20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "554DC73D-972F-4A19-A4D5-0FFBE3A62996" }, { "criteria": "cpe:2.3:a:php-survey:php-survey:2000-04-21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AECF8789-EE25-4915-BD79-831EB5492998" }, { "criteria": "cpe:2.3:a:php-survey:php-survey:2000-06-14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "390FA997-483B-47D2-9453-ED2638E43569" }, { "criteria": "cpe:2.3:a:php-survey:php-survey:2000-06-14b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60DA163D-E092-498B-B386-ED0F499E2386" }, { "criteria": "cpe:2.3:a:php-survey:php-survey:2000-06-15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D194B43-AC99-4F0D-9A3C-4D53755620CC" }, { "criteria": "cpe:2.3:a:php-survey:php-survey:prebeta2000-03-27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1D3E2A3-43BB-44EB-87C7-B056E985C7B6" } ], "operator": "OR" } ] } ]