CVE-2000-0689

Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cgi_script_center:account_manager:lite_1.0:*:*:*:*:*:*:*
cpe:2.3:a:cgi_script_center:account_manager:pro_1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:33

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html - Exploit, Vendor Advisory
References () http://www.cgiscriptcenter.com/acctlite/ - () http://www.cgiscriptcenter.com/acctlite/ -
References () http://www.osvdb.org/13341 - () http://www.osvdb.org/13341 -
References () http://www.securityfocus.com/bid/1604 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/bid/1604 - Exploit, Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/5125 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/5125 -

Information

Published : 2000-10-20 04:00

Updated : 2024-11-20 23:33


NVD link : CVE-2000-0689

Mitre link : CVE-2000-0689

CVE.ORG link : CVE-2000-0689


JSON object : View

Products Affected

cgi_script_center

  • account_manager