PT-2002-2026 · Adobe · Contentserv

Published

2002-08-31

·

Updated

2016-10-18

·

CVE-2002-1020

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Adobe Content Server version 3.0
Description: The library feature in Adobe Content Server allows a remote attacker to bypass the maximum number of loans for an eBook. This can be achieved by accessing the "Add to bookbag" feature when the server indicates that no more copies are available.
Recommendations: For Adobe Content Server version 3.0, consider restricting access to the "Add to bookbag" feature until a fix is available to prevent exploitation of this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1020

Affected Products

Contentserv