10
CVSSv2

CVE-2002-0599

Published: 18/06/2002 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Blahz-DNS 0.2 and previous versions allows remote malicious users to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.

Vulnerable Product Search on Vulmon Subscribe to Product

blahz-dns blahz-dns 0.2

Exploits

source: wwwsecurityfocuscom/bid/4618/info Blahz-DNS is a web based management tool for DNS information It is implemented in PHP, and available for Linux systems By directly calling scripts included with Blahz-DNS, it is possible to bypass the authentication check, gaining full access to the Blahz-DNS tool wwwexamplecom/dostu ...