PT-2002-1546 · Cssearch · Cssearch

CVE-2002-0495

·

Publicado

2002-08-12

·

Atualizado

2024-02-13

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions csSearch versions 2.3 and earlier
Description The issue allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter. This is done by overwriting the setup.cgi configuration file that is loaded by csSearch.cgi.
Recommendations For csSearch versions 2.3 and earlier, consider disabling the savesetup command and restricting access to the setup parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-0495

Produtos afetados

Cssearch