PT-2000-1856 · Cgi Script Center · Cgi Script Center News Update

Published

2000-12-19

·

Updated

2024-02-09

·

CVE-2000-0944

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CGI Script Center News Update version 1.1
Description The issue concerns a problem with password validation during a password change operation. Specifically, it does not properly validate the original news administration password, allowing remote attackers to modify the password without knowing the original password.
Recommendations For CGI Script Center News Update version 1.1, consider temporarily disabling the password change operation until a proper fix is available. Restrict access to the news administration interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2000-0944

Affected Products

Cgi Script Center News Update