PT-2000-1376 · Allmanage · Allmanage Website Administration

Published

2000-05-13

·

Updated

2008-09-10

·

CVE-2000-0435

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Allmanage Website administration software version 2.6
Description The issue allows remote attackers to modify user accounts or web pages by directly calling the allmanageup.pl file upload CGI script.
Recommendations For Allmanage Website administration software version 2.6, restrict access to the allmanageup.pl file upload CGI script to prevent direct calls from remote attackers.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0435

Affected Products

Allmanage Website Administration