CVE Vulnerabilities

CVE-2000-0696

Published: Oct 20, 2000 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

Affected Software

Name Vendor Start Version End Version
Solaris_answerbook2 Sun 1.3 1.3
Solaris_answerbook2 Sun 1.4 1.4
Solaris_answerbook2 Sun 1.4.1 1.4.1
Solaris_answerbook2 Sun 1.4.2 1.4.2

References