PT-2000-1106 · Allaire · Allaire Spectra

Published

2000-01-01

·

Updated

2018-05-03

·

CVE-2000-0120

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Allaire Spectra version 1.0
Description The issue allows users to bypass authentication. This is achieved by manipulating the bAuthenticated parameter in the Remote Access Service invoke.cfm template.
Recommendations For Allaire Spectra version 1.0, consider restricting access to the invoke.cfm template until a fix is available. As a temporary workaround, avoid using the bAuthenticated parameter in the affected template to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0120

Affected Products

Allaire Spectra