Vulnerability Description
The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easy Scripts Archive | Advanced Easy Homepage Creator | 1.0 |
| Easy Scripts Archive | Easy Homepage Creator | 1.0 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0350.htmlExploitPatchVendor Advisory
- http://www.iss.net/security_center/static/9696.phpVendor Advisory
- http://www.securityfocus.com/bid/5340ExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0350.htmlExploitPatchVendor Advisory
- http://www.iss.net/security_center/static/9696.phpVendor Advisory
- http://www.securityfocus.com/bid/5340ExploitVendor Advisory
FAQ
What is CVE-2002-1427?
CVE-2002-1427 is a vulnerability with a CVSS score of 7.5 (HIGH). The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.
How severe is CVE-2002-1427?
CVE-2002-1427 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1427?
Check the references section above for vendor advisories and patch information. Affected products include: Easy Scripts Archive Advanced Easy Homepage Creator, Easy Scripts Archive Easy Homepage Creator.