10
CVSSv2

CVE-2000-0757

Published: 20/10/2000 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote malicious users to gain root privileges by connecting to the service and specifying the commands to be executed.

Vulnerable Product Search on Vulmon Subscribe to Product

aptis software totalbill 3.0

Exploits

source: wwwsecurityfocuscom/bid/1555/info Aptis Software offers a billing / provisioning solution for ISPs called TotalBill One component of the TotalBill package is a network service called Sysgen that listens on or around port 9998 It allows a client connectiing to it to execute any command on the host it is running on (with whatever ...