Vulnerability Description
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pgp | Keyserver | 7.0 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0230.html
- http://www.iss.net/security_center/static/7203.phpPatchVendor Advisory
- http://www.osvdb.org/1955
- http://www.osvdb.org/4193
- http://www.pgp.com/support/product-advisories/keyserver.asp
- http://www.securityfocus.com/bid/3375
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0230.html
- http://www.iss.net/security_center/static/7203.phpPatchVendor Advisory
- http://www.osvdb.org/1955
- http://www.osvdb.org/4193
- http://www.pgp.com/support/product-advisories/keyserver.asp
- http://www.securityfocus.com/bid/3375
FAQ
What is CVE-2001-1252?
CVE-2001-1252 is a vulnerability with a CVSS score of 10.0 (HIGH). Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for...
How severe is CVE-2001-1252?
CVE-2001-1252 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1252?
Check the references section above for vendor advisories and patch information. Affected products include: Pgp Keyserver.