7.5
CVSSv2

CVE-2002-0923

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.

Vulnerable Product Search on Vulmon Subscribe to Product

cgiscript.net csnews 1.0

cgiscript.net csnews 1.0 professional

Exploits

source: wwwsecurityfocuscom/bid/4994/info csNews is a script for managing news items on a website It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems It is possible for a malicious admin user to bypass file type restrictions on the header and footer file This may result in arbitrary system files ...