CVE-2000-0696
Summary
| CVE | CVE-2000-0696 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2000-10-20 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Solaris Answerbook2 | 1.3 | All | All | All |
| Application | Sun | Solaris Answerbook2 | 1.4 | All | All | All |
| Application | Sun | Solaris Answerbook2 | 1.4.1 | All | All | All |
| Application | Sun | Solaris Answerbook2 | 1.4.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page not found – S21Sec | af854a3a-2127-422b-91ae-364da2661108 | www.s21sec.com | |
| Bugtraq: Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Solaris AnswerBook2 Administration Interface Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| archives.neohapsis.com/archives/sun/2000-q3/0001.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.