Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1867

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2002-1867
Last Modified 05 Sep 2008 04:31:43
Published 31 Dec 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-1867

Summary

The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).

Vulnerable Systems

Application

  • Bizdesign Imagefolio 2.23

  • Bizdesign Imagefolio 2.24

  • Bizdesign Imagefolio 2.26


References

BID - 4975

XF - imagefolio-setup-cgi-access(9308)

BUGTRAQ - 20020609 [LoWNOISE] ImageFolio Pro 2.2


Last Updated: 27 May 2016 10:37:31