Vulnerability Description
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dnstools Software | Dnstools | 2.0_beta3 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0390.htmlExploitPatchVendor Advisory
- http://www.dnstools.com/dnstools_2.0.1.tar.gz
- http://www.iss.net/security_center/static/8948.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/4617ExploitPatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0390.htmlExploitPatchVendor Advisory
- http://www.dnstools.com/dnstools_2.0.1.tar.gz
- http://www.iss.net/security_center/static/8948.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/4617ExploitPatchVendor Advisory
FAQ
What is CVE-2002-0613?
CVE-2002-0613 is a vulnerability with a CVSS score of 10.0 (HIGH). dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.
How severe is CVE-2002-0613?
CVE-2002-0613 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0613?
Check the references section above for vendor advisories and patch information. Affected products include: Dnstools Software Dnstools.