CVE-2003-0162

critical

Description

Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/11431

http://www.securityfocus.com/bid/6971

http://www.debian.org/security/2003/dsa-271

http://marc.info/?l=bugtraq&m=104673407728323&w=2

http://marc.info/?l=bugtraq&m=104636153214262&w=2

Details

Source: Mitre, NVD

Published: 2003-04-02

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical