7.5

CVE-2002-0324

Exploit
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Noah GrayGraymatter Version1.1
Noah GrayGraymatter Version1.1b
Noah GrayGraymatter Version1.2b
Noah GrayGraymatter Version1.21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.73% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=101465343308249&w=2
http://www.dangerousmonkey.com/dangblog/dangarch/00000051.htm
Vendor Advisory
Exploit
http://www.iss.net/security_center/static/8277.php
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/4169