Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1841

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2002-1841
Last Modified 05 Sep 2008 04:31:39
Published 31 Dec 2002 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-1841

Summary

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

Vulnerable Systems

Application

  • Noguska Nola 1.1.1

  • Noguska Nola 1.1.2


References

BID - 5116

VULN-DEV - 20020702 Re: Noguska Nola 1.1.1 [ Intranet Business Management Software ]

XF - nola-php-script-upload(9438)

VULN-DEV - 20020625 Noguska Nola 1.1.1 [ Intranet Business Management Software ]


Last Updated: 27 May 2016 10:37:30