CVE-2000-0720
Last modified
CVE-2000-0720 is a vulnerability of currently unknown severity. news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.. EPSS estimates a 6.16% chance of exploitation in the next 30 days.
Description
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gwscripts | Gwscripts News Publisher | 1.05 |
| Gwscripts | Gwscripts News Publisher | 1.05a |
| Gwscripts | Gwscripts News Publisher | 1.05b |
| Gwscripts | Gwscripts News Publisher | 1.06 |
References
- http://www.securityfocus.com/bid/1621Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/1621Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2000-0720?
How severe is CVE-2000-0720?
How do I fix CVE-2000-0720?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2000
- CVE-2000-0714umb-scheme 3.2-11 for Red Hat Linux is installed with world-…
- CVE-2000-0715DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows lo…
- CVE-2000-0716WorldClient email client in MDaemon 2.8 includes the session…
- CVE-2000-0717GoodTech FTP server allows remote attackers to cause a denia…
- CVE-2000-0718A race condition in MandrakeUpdate allows local users to mod…
- CVE-2000-0719VariCAD 7.0 is installed with world-writeable files, which a…
- CVE-2000-0721The FSserial, FlagShip_c, and FlagShip_p programs in the Fla…
- CVE-2000-0722Helix GNOME Updater helix-update 0.5 and earlier allows loca…
- CVE-2000-0723Helix GNOME Updater helix-update 0.5 and earlier does not pr…
- CVE-2000-0724The go-gnome Helix GNOME pre-installer allows local users to…
- CVE-2000-0725Zope before 2.2.1 does not properly restrict access to the g…
- CVE-2000-0726CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows r…
Are you affected by CVE-2000-0720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
