Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2002-0922
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.
0
Attacker Value
Unknown
CVE-2002-0917
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users.
0
Attacker Value
Unknown
CVE-2002-0918
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error.
0
Attacker Value
Unknown
CVE-2002-0752
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing the file.
0
Attacker Value
Unknown
CVE-2002-0751
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters.
0
Attacker Value
Unknown
CVE-2002-0495
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
0
Attacker Value
Unknown
CVE-2002-0750
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment field.
0
Attacker Value
Unknown
CVE-2002-0749
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.
0