PT-2002-2472 · Cgiscript.Net · Cgiscript.Net Csguestbook

Published

2002-12-31

·

Updated

2024-02-14

·

CVE-2002-1750

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CGISCRIPT.NET csGuestbook version 1.0
Description The issue allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. This can be exploited through the /csGuestbook.cgi API endpoint.
Recommendations For CGISCRIPT.NET csGuestbook version 1.0, consider disabling the eval function for the setup parameter in the csGuestbook.cgi script until a patch is available. Restrict access to the csGuestbook.cgi endpoint to minimize the risk of exploitation. Avoid using the setup parameter in the affected endpoint until the issue is resolved.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2002-1750

Affected Products

Cgiscript.Net Csguestbook