CVE
- Id
- 1652
- CVE No.
- CVE-2000-0074
- Status
- Candidate
- Description
- PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.
- Phase
- Proposed (20000125)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Christey, Williams
- Comments
- Frech> XF:plusmail-password-permissions | Christey> Re-read the Bugtraq post to make sure the problem is described | properly. The advisory itself is vague as to the nature of | the problem, and the exploit doesn"t help clarify too much. | Christey> Consider adding BID:2653