PT-1999-1551 · Apache · Apache

Publicado

1999-09-13

·

Atualizado

2008-09-05

·

CVE-1999-1053

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions guestbook.pl (affected versions not specified) Apache versions 1.3.9 and possibly other versions
Description The issue allows remote attackers to execute arbitrary commands due to the incomplete removal of user-inserted SSI commands by guestbook.pl. This is possible because Apache allows other closing sequences besides "-->".
Recommendations For Apache version 1.3.9, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to guestbook.pl until a patch is available. Avoid using SSI commands in guestbook.pl until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1053

Produtos afetados

Apache