Vulnerabilities > CVE-2003-0162 - Unspecified vulnerability in Ecartis 1.0.0Snapshot20021013

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ecartis
nessus

Summary

Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.

Vulnerable Configurations

Part Description Count
Application
Ecartis
1

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-271.NASL
    descriptionA problem has been discovered in ecartis, a mailing list manager, formerly known as listar. This vulnerability enables an attacker to reset the password of any user defined on the list server, including the list admins.
    last seen2020-06-01
    modified2020-06-02
    plugin id15108
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15108
    titleDebian DSA-271-1 : ecartis - unauthorized password change
  • NASL familyCGI abuses
    NASL idECARTIS_HIDDEN_USERNAME.NASL
    descriptionThe remote host is running the Ecartis Mailing List Manager web interface (lsg2.cgi). According to its version number, there is a vulnerability that allows an authenticated user to change anyone
    last seen2020-06-01
    modified2020-06-02
    plugin id11505
    published2003-03-30
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11505
    titleEcartis HTML Field Manipulation Arbitrary User Password Reset