CVE-2002-1481

Publication date

2003-03-18 05:00:00

Family

mitre

State

PUBLISHED

Description

savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.