CVE-2000-0696 describes a critical authentication bypass vulnerability in the dwhttpd web server's administration interface within Sun Solaris AnswerBook2. This flaw allows unauthenticated remote attackers to directly invoke administrative CGI scripts, enabling them to add new user accounts to the interface. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low complexity, potentially leading to unauthorized access, information disclosure, and system compromise. While not listed in CISA KEV and showing no recent community discussion or media coverage, an ExploitDB entry exists, indicating public exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:sun:solaris_answerbook2:1.3:*:*:*:*:*:*:* | ||
1.4CPE matchmatch criteria | cpe:2.3:a:sun:solaris_answerbook2:1.4:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:sun:solaris_answerbook2:1.4.1:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:sun:solaris_answerbook2:1.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.