CVE-2002-0920 Information

Description

CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.

Reference

http://online.securityfocus.com/archive/1/274727 http://www.iss.net/security_center/static/9223.php http://www.securityfocus.com/bid/4889

Share on: