Vulnerabilities > CVE-2002-1704 - Unspecified vulnerability in Zeroboard 4.1Pl2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
zeroboard
exploit available

Summary

Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code.

Vulnerable Configurations

Part Description Count
Application
Zeroboard
1

Exploit-Db

descriptionZeroboard 4.1 PHP Include File Arbitrary Command Execution Vulnerability. CVE-2002-1704. Webapps exploit for php platform
idEDB-ID:21557
last seen2016-02-02
modified2002-06-15
published2002-06-15
reporteronlooker
sourcehttps://www.exploit-db.com/download/21557/
titleZeroboard 4.1 PHP Include File Arbitrary Command Execution Vulnerability