Vulnerabilities > CVE-2002-0922 - Unspecified vulnerability in Cgiscript.Net Csnews 1.0/1.0Professional

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
cgiscript-net
exploit available

Summary

CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.

Vulnerable Configurations

Part Description Count
Application
Cgiscript.Net
2

Exploit-Db

descriptionCGIScript.net csNews 1.0 Double URL Encoding Unauthorized Administrative Access. CVE- 2002-0922,CVE-2002-0922. Webapps exploit for cgi platform
idEDB-ID:21532
last seen2016-02-02
modified2002-06-11
published2002-06-11
reporterSteve Gustin
sourcehttps://www.exploit-db.com/download/21532/
titleCGIScript.net csNews 1.0 Double URL Encoding Unauthorized Administrative Access