The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-12-30 21:00
Updated : 2016-10-17 19:27
NVD link : CVE-2002-1867
Mitre link : CVE-2002-1867
JSON object : View
CWE
Products Affected
bizdesign
- imagefolio