CVE-2000-0720 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 6.16% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-10-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gwscripts | gwscripts news publisher |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GWScripts News Publisher 1.0 - 'author.file' Write | 2000-08-29 |
References
- http://www.securityfocus.com/bid/1621
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=003301c0123b%2418f8c1a0%24953b29d4%40e8s9s4
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5169
- http://www.securityfocus.com/bid/1621
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=003301c0123b%2418f8c1a0%24953b29d4%40e8s9s4
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5169
→ the Explorer · watch your stack · NVD