5
CVSSv2

CVE-2002-0922

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CGIScript.net csNews.cgi allows remote malicious users to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.

Vulnerable Product Search on Vulmon Subscribe to Product

cgiscript.net csnews 1.0

cgiscript.net csnews 1.0_professional

Exploits

source: wwwsecurityfocuscom/bid/4993/info csNews is a script for managing news items on a website It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems Users with "public" access to the system may be able to view and modify some administration pages This is accomplished by submitting a HTTP reques ...