Lucene search

K
cveMitreCVE-2002-1084
HistoryOct 04, 2002 - 4:00 a.m.

CVE-2002-1084

2002-10-0404:00:00
mitre
web.nvd.nist.gov
23
information security
ezcontents
verifylogin
remote attackers
http post requests

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.01

Percentile

83.4%

The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.

Affected configurations

Nvd
Node
visualshapersezcontentsRange1.41
VendorProductVersionCPE
visualshapersezcontents*cpe:2.3:a:visualshapers:ezcontents:*:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.01

Percentile

83.4%

Related for CVE-2002-1084