peter bassill · operator
$ cve CVE-2002-2200 JSON

CVE-2002-2200 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.13% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
benjamin lefevredobermann forum

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD