Lucene search

K
cve[email protected]CVE-2003-0589
HistoryOct 17, 2016 - 4:00 a.m.

CVE-2003-0589

2016-10-1704:00:00
web.nvd.nist.gov
24
cve-2003-0589
remote attackers
bypass authentication
cookie
improper condition
admin.php

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.9%

admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.

Affected configurations

NVD
Node
digi-fxdigi-newsMatch1.1

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.9%

Related for CVE-2003-0589