Skip to content
Noroxi

cgiscript.net records

14 published records for vendor cgiscript.net.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      Attack profile

      All records

      14 records
      • CVE-2002-0749
        33Monitor

        CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.

        HighCVSS 7.5Proof of conceptEPSS 11%

        cgiscript.net · csmailtoAug 12, 2002

      • CVE-2002-0923
        32Monitor

        CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2)

        HighCVSS 7.5Proof of conceptEPSS 7%

        cgiscript.net · csnewsOct 4, 2002

      • CVE-2002-0919
        31Monitor

        CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title fi

        HighCVSS 7.5Proof of conceptEPSS 3%

        cgiscript.net · cspasswordOct 4, 2002

      • CVE-2002-0751
        31Monitor

        CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (

        HighCVSS 7.5No exploitEPSS 3%

        cgiscript.net · csmailtoAug 12, 2002

      • CVE-2002-0917
        31Monitor

        CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download th

        HighCVSS 7.5No exploitEPSS 2%

        cgiscript.net · cspasswordOct 4, 2002

      • CVE-2002-0924
        30Monitor

        CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text

        HighCVSS 7.5No exploitEPSS 1%

        cgiscript.net · csnewsOct 4, 2002

      • CVE-2002-0918
        21Monitor

        CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the sc

        MediumCVSS 5.0Proof of conceptEPSS 3%

        cgiscript.net · cspasswordOct 4, 2002

      • CVE-2002-0922
        21Monitor

        CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) defaul

        MediumCVSS 5.0Proof of conceptEPSS 3%

        cgiscript.net · csnewsOct 4, 2002

      • CVE-2004-0665
        21Monitor

        csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the we

        MediumCVSS 5.0Proof of conceptEPSS 3%

        cgiscript.net · csfaqAug 6, 2004

      • CVE-2002-1751
        21Monitor

        csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is pr

        MediumCVSS 5.0No exploitEPSS 2%

        cgiscript.net · cslivesupportDec 31, 2002

      • CVE-2002-0750
        21Monitor

        CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment

        MediumCVSS 5.0No exploitEPSS 2%

        cgiscript.net · csmailtoAug 12, 2002

      • CVE-2002-0752
        21Monitor

        CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attack

        MediumCVSS 5.0No exploitEPSS 2%

        cgiscript.net · csmailtoAug 12, 2002

      • CVE-2002-0921
        20Monitor

        CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other con

        MediumCVSS 5.0No exploitEPSS 1%

        cgiscript.net · csnewsOct 4, 2002

      • CVE-2002-0920
        20Monitor

        CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which c

        MediumCVSS 5.1No exploitEPSS 1%

        cgiscript.net · cspasswordOct 4, 2002