CVE Vulnerabilities

CVE-2002-1867

Published: Dec 31, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).

Affected Software

Name Vendor Start Version End Version
Imagefolio Bizdesign 2.23 (including) 2.23 (including)
Imagefolio Bizdesign 2.24 (including) 2.24 (including)
Imagefolio Bizdesign 2.26 (including) 2.26 (including)

References