CVE-2002-1726

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2002
Last modified:
03/04/2025

Description

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:brokenbytes:photodb:1.4:*:*:*:*:*:*:*