Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr7c-vmw2-482c

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

EPSS

Процентиль: 87%
0.03638
Низкий

Связанные уязвимости

nvd
почти 25 лет назад

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

EPSS

Процентиль: 87%
0.03638
Низкий