CVE-2000-0431
UnknownEPSS 1.40%
Last modified
CVE-2000-0431 is a vulnerability of currently unknown severity. Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Cobalt Raq 2 | All versions |
| Sun | Cobalt Raq 3i | All versions |
References
- http://www.securityfocus.com/bid/1238Patch, Vendor Advisory
- http://www.securityfocus.com/bid/1238Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2000-0431?
Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.
How severe is CVE-2000-0431?
Severity scoring for CVE-2000-0431 is pending analysis. The EPSS model estimates a 1.40% probability of exploitation in the next 30 days.
How do I fix CVE-2000-0431?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2000
- CVE-2000-0425Buffer overflow in the Web Archives component of L-Soft LIST…
- CVE-2000-0426UltraBoard 1.6 and other versions allow remote attackers to …
- CVE-2000-0427The Aladdin Knowledge Systems eToken device allows attackers…
- CVE-2000-0428Buffer overflow in the SMTP gateway for InterScan Virus Wall…
- CVE-2000-0429A backdoor password in Cart32 3.0 and earlier allows remote …
- CVE-2000-0430Cart32 allows remote attackers to access sensitive debugging…
- CVE-2000-0432The calender.pl and the calendar_admin.pl calendar scripts b…
- CVE-2000-0433The SuSE aaa_base package installs some system accounts with…
- CVE-2000-0434The administrative password for the Allmanage web site admin…
- CVE-2000-0435The allmanageup.pl file upload CGI script in the Allmanage W…
- CVE-2000-0436MetaProducts Offline Explorer 1.2 and earlier allows remote …
- CVE-2000-0437Buffer overflow in the CyberPatrol daemon "cyberdaemon" used…
Are you affected by CVE-2000-0431?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
