First published: Thu Sep 21 2000(Updated: )
The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Solaris Answerbook2 | =1.4 | |
Sun Solaris Answerbook2 | =1.4.1 | |
Sun Solaris Answerbook2 | =1.4.2 | |
Sun Solaris Answerbook2 | =1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.