20001027 CGI-Bug: News Update 1.1 administration password bugmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html CVE-2000-0944
CRITICAL
News Update 1.1 - Change Admin Password
Record summary
CVE-2000-0944 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNews Update 1.1 - Change Admin PasswordExploitDB exploitby morpheus[bd]Not analyzed1 file
References
41881vdb entry
http://www.securityfocus.com/bid/1881 news-update-bypass-password(5433)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5433 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0944