CVE-2000-0944
critical · 9.8CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
9.8
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2000-12-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-522
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cgi | script_center_news_update | 1.1 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html
- http://www.securityfocus.com/bid/1881
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5433
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html
- http://www.securityfocus.com/bid/1881
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5433
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-0944