CVE-2001-0527

DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dcscripts:dcforum:6.0:*:*:*:*:*:*:*
cpe:2.3:a:dcscripts:dcforum_2000:1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:35

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html - Exploit, Vendor Advisory
References () http://www.dcscripts.com/dcforum/dcfNews/167.html - Patch () http://www.dcscripts.com/dcforum/dcfNews/167.html - Patch
References () http://www.osvdb.org/480 - () http://www.osvdb.org/480 -
References () http://www.securityfocus.com/bid/2728 - () http://www.securityfocus.com/bid/2728 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6538 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/6538 -

Information

Published : 2001-08-14 04:00

Updated : 2024-11-20 23:35


NVD link : CVE-2001-0527

Mitre link : CVE-2001-0527

CVE.ORG link : CVE-2001-0527


JSON object : View

Products Affected

dcscripts

  • dcforum
  • dcforum_2000