1621vdb entry
http://www.securityfocus.com/bid/1621 CVE-2000-0720
GWScripts News Publisher 1.0 - 'author.file' Write
Record summary
CVE-2000-0720 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGWScripts News Publisher 1.0 - 'author.file' WriteExploitDB exploitby n30Not analyzed1 file
References
5securityfocus.com
http://www.securityfocus.com/templates/archive.pike?list=1&msg=003301c0123b$18f8c1a0$953b29d4@e8s9s4 20000829 News Publisher CGI Vulnerabilitymailing list
http://www.securityfocus.com/templates/archive.pike?list=1&msg=003301c0123b%2418f8c1a0%24953b29d4%40e8s9s4 news-publisher-add-author(5169)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5169 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0720