CVE-2002-2335

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
31/12/2002
Last modified:
03/04/2025

Description

Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:john_drake:killer_protection:1.0:*:*:*:*:*:*:*