10

CVE-2001-0527

Exploit
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DcscriptsDcforum Version6.0
DcscriptsDcforum 2000 Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.54% 0.903
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html
Vendor Advisory
Exploit
http://www.dcscripts.com/dcforum/dcfNews/167.html
Patch
http://www.osvdb.org/480
http://www.securityfocus.com/bid/2728
https://exchange.xforce.ibmcloud.com/vulnerabilities/6538