CVE-2000-0435 describes a critical vulnerability in the allmanageup.pl CGI script within Allmanage Website administration software version 2.6. This flaw allows remote, unauthenticated attackers to directly invoke the script, enabling unauthorized modification of user accounts or web page content. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector, low complexity, and potential for partial compromise of confidentiality, integrity, and availability. Despite its age and severity, there is no evidence of active exploitation, publicly available exploit code, or community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6CPE matchmatch criteria | cpe:2.3:a:matthew_redman:allmanage:2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.