{"api_version":"1","generated_at":"2026-07-23T03:24:13+00:00","cve":"CVE-2002-2045","urls":{"html":"https://cve.report/CVE-2002-2045","api":"https://cve.report/api/cve/CVE-2002-2045.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-2045","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-2045"},"summary":{"title":"CVE-2002-2045","description":"x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8466","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8466","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ifrance.com/kitetoua/tuto/x_holes.txt","name":"http://www.ifrance.com/kitetoua/tuto/x_holes.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8467","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4280","name":"http://www.securityfocus.com/bid/4280","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"X-Stat PHPInfo Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1003827","name":"http://securitytracker.com/id?1003827","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - X-stat Log File Analysis Tool Has Multiple Vulnerabilities That Allow Remote Users to Obtain Information About the System and Conduct Cross-Site Scripting Attacks Against x-stat Administrators","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4279","name":"http://www.securityfocus.com/bid/4279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"X-Stat Path Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://seclists.org/lists/vuln-dev/2002/Mar/0156.html","name":"http://seclists.org/lists/vuln-dev/2002/Mar/0156.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Vulnerability Development: X_holes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-2045","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-2045","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"2045","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xqus","cpe5":"x-stat","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2045","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xqus","cpe5":"x-stat","cpe6":"2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:51:17.523Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020313 X_holes","tags":["mailing-list","x_refsource_VULN-DEV","x_transferred"],"url":"http://seclists.org/lists/vuln-dev/2002/Mar/0156.html"},{"name":"4279","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4279"},{"name":"4280","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4280"},{"name":"1003827","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1003827"},{"name":"xstat-phpinfo-reveal-info(8467)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8467"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ifrance.com/kitetoua/tuto/x_holes.txt"},{"name":"xstat-action-reveal-path(8466)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8466"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-03-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020313 X_holes","tags":["mailing-list","x_refsource_VULN-DEV"],"url":"http://seclists.org/lists/vuln-dev/2002/Mar/0156.html"},{"name":"4279","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4279"},{"name":"4280","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4280"},{"name":"1003827","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1003827"},{"name":"xstat-phpinfo-reveal-info(8467)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8467"},{"tags":["x_refsource_MISC"],"url":"http://www.ifrance.com/kitetoua/tuto/x_holes.txt"},{"name":"xstat-action-reveal-path(8466)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8466"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-2045","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020313 X_holes","refsource":"VULN-DEV","url":"http://seclists.org/lists/vuln-dev/2002/Mar/0156.html"},{"name":"4279","refsource":"BID","url":"http://www.securityfocus.com/bid/4279"},{"name":"4280","refsource":"BID","url":"http://www.securityfocus.com/bid/4280"},{"name":"1003827","refsource":"SECTRACK","url":"http://securitytracker.com/id?1003827"},{"name":"xstat-phpinfo-reveal-info(8467)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8467"},{"name":"http://www.ifrance.com/kitetoua/tuto/x_holes.txt","refsource":"MISC","url":"http://www.ifrance.com/kitetoua/tuto/x_holes.txt"},{"name":"xstat-action-reveal-path(8466)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8466"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-2045","datePublished":"2005-07-14T04:00:00.000Z","dateReserved":"2005-07-14T00:00:00.000Z","dateUpdated":"2024-08-08T03:51:17.523Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xqus:x-stat:2.2:*:*:*:*:*:*:*","matchCriteriaId":"7DE79EB2-0C14-4282-B901-28FA360C2B76"},{"vulnerable":true,"criteria":"cpe:2.3:a:xqus:x-stat:2.3:*:*:*:*:*:*:*","matchCriteriaId":"90C17C73-CED5-4EAA-9672-1F528126D50C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"2045","Ordinal":"1","Title":"CVE-2002-2045","CVE":"CVE-2002-2045","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"2045","Ordinal":"1","NoteData":"x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.","Type":"Description","Title":"CVE-2002-2045"},{"CveYear":"2002","CveId":"2045","Ordinal":"2","NoteData":"2005-07-14","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"2045","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}