PT-2000-1376 · Allmanage · Allmanage Website Administration
Published
2000-05-13
·
Updated
2008-09-10
·
CVE-2000-0435
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Allmanage Website administration software version 2.6
Description
The issue allows remote attackers to modify user accounts or web pages by directly calling the allmanageup.pl file upload CGI script.
Recommendations
For Allmanage Website administration software version 2.6, restrict access to the allmanageup.pl file upload CGI script to prevent direct calls from remote attackers.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Allmanage Website Administration