CVE-2002-2298

Atthat.com Thatware < 0.5.3 - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/2166

Scores

EPSS 0.0149
EPSS Percentile 80.8%

Classification

CWE
CWE-94
Status draft

Affected Products (1)

atthat.com/thatware < 0.5.3

Timeline

Published Dec 31, 2002
Tracked Since Feb 18, 2026