10
CVSSv2

CVE-2002-2425

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Sun AnswerBook2 1.2 up to and including 1.4.2 allows remote malicious users to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

Vulnerable Product Search on Vulmon Subscribe to Product

sun solaris answerbook2 1.2

sun solaris answerbook2 1.4

sun solaris answerbook2 1.4.1

sun solaris answerbook2 1.4.2

sun solaris answerbook2 1.3

Exploits

source: wwwsecurityfocuscom/bid/5383/info Sun Microsystems AnswerBook2 allows users to view Sun documentation through a web browser, and is available for Solaris AnswerBook2 includes an administrative web interface Reportedly, it is possible to access these scripts without authorization, and add a new administrative user of the AnswerB ...