VulnerabilityModified
CVE-2000-0769
O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.
HIGH 7.5EPSS 1.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- oreilly/website pro
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=96715834610888&w=2
- http://www.securityfocus.com/bid/1611Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=96715834610888&w=2
- http://www.securityfocus.com/bid/1611Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.