Vulnerability Name: | CVE-2000-0696 (CCN-5069) | ||||||||
Assigned: | 2000-08-08 | ||||||||
Published: | 2000-08-08 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Aug 08 2000 - 02:48:04 CDT Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server Source: SUN Type: Patch, Vendor Advisory 00196 Source: CCN Type: Sun Microsystems, Inc. Security Bulletin #00196 AnswerBook2 Source: MITRE Type: CNA CVE-2000-0696 Source: BUGTRAQ Type: UNKNOWN 20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server Source: CCN Type: CIAC Information Bulletin L-031 Sun AnswerBook2 Vulnerability Source: CCN Type: CIAC Information Bulletin O-012 Sun Vulnerability in Solaris "AnswerBook2 Documentation" Server Daemon Source: CCN Type: OSVDB ID: 8679 Sun AnswerBook2 Web Server dwhttpd Arbitrary Account Creation Source: MISC Type: UNKNOWN http://www.s21sec.com/en/avisos/s21sec-004-en.txt Source: BID Type: Exploit, Patch, Vendor Advisory 1554 Source: CCN Type: BID-1554 Solaris AnswerBook2 Administration Interface Access Vulnerability Source: CCN Type: Sun Alert ID: 23412 Vulnerability in Solaris "AnswerBook2 Documentation" Server Daemon Source: XF Type: UNKNOWN solaris-answerbook2-admin-interface(5069) Source: XF Type: UNKNOWN solaris-answerbook2-admin-interface(5069) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |