PT-2002-2404 · Cgi · Cgi Online Worldweb Shopping

Publicado

2002-12-31

·

Atualizado

2017-07-11

·

CVE-2002-1680

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CGI Online Worldweb Shopping version 1.1
Description A cross-site scripting issue allows remote attackers to execute arbitrary script as other users. This is achieved by injecting script into API endpoints such as "diagnose.cgi" or "compatible.cgi".
Recommendations For version 1.1, consider disabling access to the "diagnose.cgi" and "compatible.cgi" endpoints until a patch is available to prevent exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1680

Produtos afetados

Cgi Online Worldweb Shopping