CVE-2002-0734
Last modified
CVE-2002-0734 is a vulnerability of currently unknown severity. b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program stored on a remote server.. EPSS estimates a 7.01% chance of exploitation in the next 30 days.
Description
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program stored on a remote server.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Michel Valdrighi | B2 | 0.6_pre |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0027.htmlExploit, Patch, Vendor Advisory
- http://cafelog.com/Vendor Advisory
- http://www.iss.net/security_center/static/9013.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4673Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0027.htmlExploit, Patch, Vendor Advisory
- http://cafelog.com/Vendor Advisory
- http://www.iss.net/security_center/static/9013.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4673Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0734?
How severe is CVE-2002-0734?
How do I fix CVE-2002-0734?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0728Buffer overflow in the progressive reader for libpng 1.2.x b…
- CVE-2002-0729Microsoft SQL Server 2000 allows remote attackers to cause a…
- CVE-2002-0730Cross-site scripting vulnerability in guestbook.pl for Phili…
- CVE-2002-0731Cross-site scripting vulnerability in demonstration scripts …
- CVE-2002-0732Cross-site scripting vulnerability in MyGuestbook 1.0 allows…
- CVE-2002-0733Cross-site scripting vulnerability in thttpd 2.20 and earlie…
- CVE-2002-0735Format string vulnerability in the logging() function in C-N…
- CVE-2002-0736Microsoft BackOffice 4.0 and 4.5, when configured to be acce…
- CVE-2002-0737Sambar web server before 5.2 beta 1 allows remote attackers …
- CVE-2002-0738MHonArc 2.5.2 and earlier does not properly filter Javascrip…
- CVE-2002-0739Cross-site scripting in PostCalendar 3.02 allows remote atta…
- CVE-2002-0740Buffer overflow in slrnpull for the SLRN package, when insta…
Are you affected by CVE-2002-0734?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
