PT-2002-1546 · Cssearch · Cssearch

Published

2002-08-12

·

Updated

2024-02-13

·

CVE-2002-0495

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions csSearch versions 2.3 and earlier
Description The issue allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter. This is done by overwriting the setup.cgi configuration file that is loaded by csSearch.cgi.
Recommendations For csSearch versions 2.3 and earlier, consider disabling the savesetup command and restricting access to the setup parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2002-0495

Affected Products

Cssearch