CVE
- Id
- 2333
- CVE No.
- CVE-2000-0757
- Status
- Candidate
- Description
- The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.
- Phase
- Proposed (20000921)
- Votes
- ACCEPT(2) Baker, Levy | NOOP(4) Christey, Cole, Wall, Williams
- Comments
- Christey> XF:totalbill-remote-execution | http://xforce.iss.net/static/5068.php