10
CVSSv2

CVE-2002-0495

Published: 12/08/2002 Updated: 13/02/2024
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

csSearch.cgi in csSearch 2.3 and previous versions allows remote malicious users to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

cgiscript cssearch professional

Exploits

source: wwwsecurityfocuscom/bid/4368/info csSearch is a website search script, written in Perl It will run on most Unix and Linux variants, as well as Microsoft operating systems csSearch is prone to an issue which may enable an attacker to execute Perl code with the privileges of the webserver process For exploitation to be successf ...