Record summary

CVE-2000-0720 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGWScripts News Publisher 1.0 - 'author.file' WriteExploitDB exploitby n30Not analyzed1 file
ExploitDB

PoC details

References

5