Exploitation Summary
EIP tracks 2 public exploits for CVE-2000-0688. PoCs published by n30, teleh0r.
AI-analyzed exploit summary This HTML form exploits an authentication bypass vulnerability in CGI Script Centers' Subscribe Me Lite by allowing any remote user to set a new administrative password without prior authentication. The exploit directly submits a new password to the vulnerable `subscribe.pl` script, granting full administrative privileges.
Description
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.
Exploits (2)
This HTML form exploits an authentication bypass vulnerability in CGI Script Centers' Subscribe Me Lite by allowing any remote user to set a new administrative password without prior authentication. The exploit directly submits a new password to the vulnerable `subscribe.pl` script, granting full administrative privileges.
This exploit targets CVE-2000-0688, an authentication bypass vulnerability in CGI Script Centers' Subscribe Me Lite 2.0. It sends a crafted POST request to change the administrative password without authentication, granting full administrative privileges.