7.5
CVSSv2

CVE-2002-1427

Published: 11/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote malicious users to modify home pages of other users.

Vulnerable Product Search on Vulmon Subscribe to Product

easy scripts archive advanced easy homepage creator 1.0

easy scripts archive easy homepage creator 1.0

Exploits

source: wwwsecurityfocuscom/bid/5340/info The vulnerability has been reported for Easy Homepage Creator It is possible for an atttacker to modify any user's home page The vulnerability is the result of Homepage Creator failing to properly authenticate users who wish to edit home pages <html><center> <h1>Easy Homepag ...