VDB
CVE-2002-0081
CVE-2002-0081
PUBLISHED
CVSS 7.5 HIGH
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled.
EPSS 52.39% · 98.0th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
52.39%
98.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 3.0, 4.0.6, 4.1.0 |
| n/a | n/a | n/a |
Timeline
- Mar 8, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- VU#297363 third-party-advisory
- MDKSA-2002:017 vendor-advisory
- 20020225 Re: Rumours about Apache 1.3.22 exploits mailing-list
- php-file-upload-overflow(8281) vdb
- HPSBTL0203-028 vendor-advisory
- 20020227 Advisory 012002: PHP remote vulnerabilities mailing-list
- DSA-115 vendor-advisory
- 20020228 TSLSA-2002-0033 - mod_php mailing-list
- http://www.php.net/downloads.php url
- CA-2002-05 third-party-advisory
- CLA-2002:468 vendor-advisory
- 4183 vdb
- http://security.e-matters.de/advisories/012002.html url
- ESA-20020301-006 vendor-advisory
- SuSE-SA:2002:007 vendor-advisory
- 20020227 PHP remote vulnerabilities mailing-list
- RHSA-2002:035 vendor-advisory
- RHSA-2002:040 vendor-advisory
- 20020304 Apache+php Proof of Concept Exploit mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2002-0081 advisory