5
CVSSv2

CVE-2002-0918

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote malicious users to obtain the information via a "remove" option in the command parameter, which generates an error.

Vulnerable Product Search on Vulmon Subscribe to Product

cgiscript.net cspassword 1.0

Exploits

source: wwwsecurityfocuscom/bid/4887/info CGIScriptnet provides various webmaster related tools and is maintained by Mike Barone and Andy Angrick A vulnerability has been reported in the csPasswordcgi script developed by CGIScriptnet that discloses potentially sensitive information to a user When an error occurs with the csPassword ...