CVE-2000-0720

GWScripts News Publisher - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0720. PoCs published by n30.

AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in GWScripts News Publisher by spoofing the HTTP_REFERER header to add an arbitrary author account. The script sends a crafted POST request to the target CGI script, bypassing the intended access control mechanism.

Description

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

Exploits (1)

exploitdb WORKING POC VERIFIED
by n30 · perlremotecgi
https://www.exploit-db.com/exploits/20183

This exploit leverages an authentication bypass vulnerability in GWScripts News Publisher by spoofing the HTTP_REFERER header to add an arbitrary author account. The script sends a crafted POST request to the target CGI script, bypassing the intended access control mechanism.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: GWScripts News Publisher (versions 1.05, 1.05a, 1.05b, 1.06)
No auth needed
Prerequisites: Network access to the target CGI script · Target software must be running a vulnerable version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5169
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1621

Scores

EPSS 0.0616
EPSS Percentile 92.6%

Details

Status published
Products (4)
gwscripts/gwscripts_news_publisher 1.05
gwscripts/gwscripts_news_publisher 1.05a
gwscripts/gwscripts_news_publisher 1.05b
gwscripts/gwscripts_news_publisher 1.06
Published Oct 20, 2000
Tracked Since Feb 18, 2026