Vulnerabilities > CVE-2002-1867 - Unspecified vulnerability in Bizdesign Imagefolio 2.23/2.24/2.26

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
bizdesign

Summary

The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).

Vulnerable Configurations

Part Description Count
Application
Bizdesign
3