Security Advisory

CVE-2002-1867

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-06-28 04:00:00
Last updated 2024-08-08 03:43:32
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).