CVE-2000-0720 - CVE House
Back to Database
Status published Medium CVE-2000-0720

news.cgi in GWScripts News Publisher does not properly authenticate requests...

Vulnerability Description

news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2000-0720

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

gwscripts news publisher
Vulnerable Versions:
1.05, 1.05a, 1.05b, 1.06

Timeline

Official Publish: May 7th, 2001
Last Modified: August 8th, 2024
Added to House: July 17th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.