CVE-2002-0324 describes a critical vulnerability in Greymatter 1.21c and earlier, specifically when the Bookmarklet feature is enabled. An attacker can gain administrative privileges by guessing the name of a gmrightclick-*.reg file, which contains the administrator's cleartext password, and retrieving it from the web server before the administrator clears it. This vulnerability has a CVSS score of 7.5, indicating high severity with a network attack vector, low complexity, and potential for partial confidentiality, integrity, and availability impact. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1CPE matchmatch criteria | cpe:2.3:a:noah_gray:graymatter:1.1:*:*:*:*:*:*:* | ||
1.1bCPE matchmatch criteria | cpe:2.3:a:noah_gray:graymatter:1.1b:*:*:*:*:*:*:* | ||
1.2bCPE matchmatch criteria | cpe:2.3:a:noah_gray:graymatter:1.2b:*:*:*:*:*:*:* | ||
1.21CPE matchmatch criteria | cpe:2.3:a:noah_gray:graymatter:1.21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.