CVE-2002-1726

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.

Scoring

CVSS base score
0.03
EPSS probability
0.64%
Published
2005-06-21
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs