Vulnerabilities > CVE-2002-0923 - Unspecified vulnerability in Cgiscript.Net Csnews 1.0/1.0Professional
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | CGIScript.net csNews 1.0 Header File Type Restriction Bypass Vulnerability. CVE-2002-0923. Webapps exploit for cgi platform |
id | EDB-ID:21533 |
last seen | 2016-02-02 |
modified | 2002-06-11 |
published | 2002-06-11 |
reporter | Steve Gustin |
source | https://www.exploit-db.com/download/21533/ |
title | CGIScript.net csNews 1.0 Header File Type Restriction Bypass Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | CSNEWS.NASL |
description | The CSNews.cgi exists on this web server. Some versions of this file are vulnerable to remote exploit. An attacker can submit a specially crafted web form, which can display the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11726 |
published | 2003-06-11 |
reporter | This script is Copyright (C) 2003-2018 John Lampe |
source | https://www.tenable.com/plugins/nessus/11726 |
title | CGIScript.net csNews.cgi Advanced Settings Multiple Parameter Arbitrary File Retrieval |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0091.html
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0091.html
- http://www.iss.net/security_center/static/9333.php
- http://www.iss.net/security_center/static/9333.php
- http://www.securityfocus.com/bid/4994
- http://www.securityfocus.com/bid/4994