peter bassill · operator
$ cve CVE-2000-0688 JSON

CVE-2000-0688 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.8% (pctl 95)

Patch early

A public exploit exists.

Description

Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.81% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2000-10-20
Last modified2026-06-16

Affected (1)

VendorProduct
cgi script centersubscribe me lite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD