Vulnerabilities > CVE-2000-0720 - Unspecified vulnerability in Gwscripts News Publisher

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
gwscripts
exploit available

Summary

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

Exploit-Db

descriptionGWScripts News Publisher 1.0 author.file Write Vulnerability. CVE-2000-0720. Remote exploit for cgi platform
idEDB-ID:20183
last seen2016-02-02
modified2000-08-29
published2000-08-29
reportern30
sourcehttps://www.exploit-db.com/download/20183/
titleGWScripts News Publisher 1.0 - author.file Write Vulnerability