peter bassill · operator
$ cve CVE-2000-0696 JSON

CVE-2000-0696 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.18% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2000-10-20
Last modified2026-06-16

Affected (1)

VendorProduct
sunsolaris answerbook2

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD