CVE-2000-0689 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.8% (pctl 95)
Patch early
A public exploit exists.
Description
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.81% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-10-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cgi script center | account manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (1) | 2000-08-23 |
| exploit-db | CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (2) | 2000-08-23 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html
- http://www.cgiscriptcenter.com/acctlite/
- http://www.osvdb.org/13341
- http://www.securityfocus.com/bid/1604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5125
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html
- http://www.cgiscriptcenter.com/acctlite/
- http://www.osvdb.org/13341
- http://www.securityfocus.com/bid/1604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5125
→ the Explorer · watch your stack · NVD