CVE-2002-0066
Summary
| CVE | CVE-2002-0066 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-04-22 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Funk Software Proxy Host 3.x before 3.09A creates a Named Pipe that does not require authentication and is installed with insecure access control, which allows local and possibly remote users to use the Proxy Host's configuration utilities and gain privileges. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bindview | Netrc | 1.0 | All | All | All |
| Application | Bindview | Netrc | 3.06 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.0 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.06 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.09 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Funk Software Proxy Named Pipe Weak Permissions Arbitrary Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Razor: Security Advisories and Publications | af854a3a-2127-422b-91ae-364da2661108 | razor.bindview.com | Patch, Vendor Advisory |
| ISS X-Force Database: funk-proxy-named-pipe (8793): Funk Software Proxy Named Pipe insecure permissions | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.