CVE-2000-0688 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.8% (pctl 95)
Patch early
A public exploit exists.
Description
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.81% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-10-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cgi script center | subscribe me lite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (1) | 2000-08-23 |
| exploit-db | CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (2) | 2000-08-23 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0292.html
- http://marc.info/?l=bugtraq&m=96722957421029&w=2
- http://www.cgiscriptcenter.com/subscribe/
- http://www.securityfocus.com/bid/1607
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0292.html
- http://marc.info/?l=bugtraq&m=96722957421029&w=2
- http://www.cgiscriptcenter.com/subscribe/
- http://www.securityfocus.com/bid/1607
→ the Explorer · watch your stack · NVD