CVE-2001-1252

critical

Description

Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory.

References

http://www.securityfocus.com/bid/3375

http://www.pgp.com/support/product-advisories/keyserver.asp

http://www.osvdb.org/4193

http://www.osvdb.org/1955

http://www.iss.net/security_center/static/7203.php

http://archives.neohapsis.com/archives/bugtraq/2001-09/0230.html

Details

Source: Mitre, NVD

Published: 2001-09-28

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.01116