CVE-2000-0696
Published Oct 20, 2000
Last updated 7 years ago
Overview
- Description
- The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sun:solaris_answerbook2:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A70C7D11-5DEA-473C-AB5A-C3676EAAE668" }, { "criteria": "cpe:2.3:a:sun:solaris_answerbook2:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09366485-E68C-4E5B-8C76-FD6D8CD48B67" }, { "criteria": "cpe:2.3:a:sun:solaris_answerbook2:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E03C0EB-3336-4CF9-8088-CD90E768B1A7" }, { "criteria": "cpe:2.3:a:sun:solaris_answerbook2:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D613BAC-1341-4B6D-971A-9CB9FE4342EF" } ], "operator": "OR" } ] } ]