CVE Vulnerabilities

CVE-2000-0689

Published: Oct 20, 2000 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.

Affected Software

Name Vendor Start Version End Version
Account_manager Cgi_script_center lite_1.0 (including) lite_1.0 (including)
Account_manager Cgi_script_center pro_1.0 (including) pro_1.0 (including)

References