PT-2000-1324 · Gossamer Threads · Gossamer Threads Dbman
Published
2000-05-05
·
Updated
2024-02-14
·
CVE-2000-0381
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Gossamer Threads DBMan version db.cgi
Description
The issue allows remote attackers to view environmental variables and setup information. This is achieved by referencing a non-existing database in the
db parameter.Recommendations
For Gossamer Threads DBMan version db.cgi, consider restricting access to the db.cgi script until a patch is available. As a temporary workaround, avoid using the
db parameter with non-existing database references to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gossamer Threads Dbman