10
CVSSv2

CVE-2001-0527

Published: 14/08/2001 Updated: 10/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

DCScripts DCForum versions 2000 and previous versions allow a remote malicious user to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.

Vulnerable Product Search on Vulmon Subscribe to Product

dcscripts dcforum 6.0

dcscripts dcforum 2000 1.0

Exploits

#source: wwwsecurityfocuscom/bid/2728/info # #DCForum is a commercial cgi script from DCScripts which is designed to facilitate web-based threaded discussion forums # #Versions of DCForum are vulnerable to attacks which can yield an elevation of privileges and remote execution of arbitrary commands # #DCForum maintains a file containing ...