CVE-2000-0435
UnknownEPSS 1.61%
Last modified
CVE-2000-0435 is a vulnerability of currently unknown severity. The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.. EPSS estimates a 1.61% chance of exploitation in the next 30 days.
Description
The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matthew Redman | Allmanage | 2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2000-0435?
The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.
How severe is CVE-2000-0435?
Severity scoring for CVE-2000-0435 is pending analysis. The EPSS model estimates a 1.61% probability of exploitation in the next 30 days.
How do I fix CVE-2000-0435?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2000
- CVE-2000-0429A backdoor password in Cart32 3.0 and earlier allows remote …
- CVE-2000-0430Cart32 allows remote attackers to access sensitive debugging…
- CVE-2000-0431Cobalt RaQ2 and RaQ3 does not properly set the access permis…
- CVE-2000-0432The calender.pl and the calendar_admin.pl calendar scripts b…
- CVE-2000-0433The SuSE aaa_base package installs some system accounts with…
- CVE-2000-0434The administrative password for the Allmanage web site admin…
- CVE-2000-0436MetaProducts Offline Explorer 1.2 and earlier allows remote …
- CVE-2000-0437Buffer overflow in the CyberPatrol daemon "cyberdaemon" used…
- CVE-2000-0438Buffer overflow in fdmount on Linux systems allows local use…
- CVE-2000-0439Internet Explorer 4.0 and 5.0 allows a malicious web site to…
- CVE-2000-0440NetBSD 1.4.2 and earlier allows remote attackers to cause a …
- CVE-2000-0441Vulnerability in AIX 3.2.x and 4.x allows local users to gai…
Are you affected by CVE-2000-0435?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
