peter bassill · operator
$ cve CVE-2000-0720 JSON

CVE-2000-0720 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)

Patch early

A public exploit exists.

Description

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS6.16% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2000-10-20
Last modified2026-06-16

Affected (1)

VendorProduct
gwscriptsgwscripts news publisher

Public exploits

SourceTitleDate
exploit-dbGWScripts News Publisher 1.0 - 'author.file' Write2000-08-29

References

→ the Explorer  ·  watch your stack  ·  NVD