VulnerabilityModified
CVE-2001-0086
CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.
MEDIUM 5.0EPSS 1.61%
Does this matter?
Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.
Description
CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.61% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- cgi script center/subscribe me lite
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.htmlVendor Advisory
- http://www.securityfocus.com/bid/2108Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5735
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.htmlVendor Advisory
- http://www.securityfocus.com/bid/2108Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5735
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.