CVE-2003-0731
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.
Date published : 2003-09-04
http://www.securityfocus.com/archive/1/333028
http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml
