CVE-2000-0944
CRITICALCGI Script Center News Update 1.1 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0944. PoCs published by morpheus[bd].
AI-analyzed exploit summary This exploit targets a password change vulnerability in News Update 1.1 by sending a crafted HTTP POST request to the CGI script. It bypasses authentication to set a new password for the news update form.
Description
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
Exploits (1)
This exploit targets a password change vulnerability in News Update 1.1 by sending a crafted HTTP POST request to the CGI script. It bypasses authentication to set a new password for the news update form.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H