cgiscript.net records
14 published records for vendor cgiscript.net.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2002-0749Proof of concept | CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.cgiscript.net · csmailto | High7.5 | — | 11.0% | Aug 12, 2002 |
32Monitor | CVE-2002-0923Proof of concept | CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2)cgiscript.net · csnews | High7.5 | — | 7.0% | Oct 4, 2002 |
31Monitor | CVE-2002-0919Proof of concept | CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title ficgiscript.net · cspassword | High7.5 | — | 3.1% | Oct 4, 2002 |
31Monitor | CVE-2002-0751No exploit | CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (cgiscript.net · csmailto | High7.5 | — | 2.7% | Aug 12, 2002 |
31Monitor | CVE-2002-0917No exploit | CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download thcgiscript.net · cspassword | High7.5 | — | 2.4% | Oct 4, 2002 |
30Monitor | CVE-2002-0924No exploit | CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text cgiscript.net · csnews | High7.5 | — | 1.4% | Oct 4, 2002 |
21Monitor | CVE-2002-0918Proof of concept | CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the sccgiscript.net · cspassword | Medium5.0 | — | 3.5% | Oct 4, 2002 |
21Monitor | CVE-2002-0922Proof of concept | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) defaulcgiscript.net · csnews | Medium5.0 | — | 3.2% | Oct 4, 2002 |
21Monitor | CVE-2004-0665Proof of concept | csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the wecgiscript.net · csfaq | Medium5.0 | — | 2.9% | Aug 6, 2004 |
21Monitor | CVE-2002-1751No exploit | csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is prcgiscript.net · cslivesupport | Medium5.0 | — | 2.1% | Dec 31, 2002 |
21Monitor | CVE-2002-0750No exploit | CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment cgiscript.net · csmailto | Medium5.0 | — | 2.1% | Aug 12, 2002 |
21Monitor | CVE-2002-0752No exploit | CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackcgiscript.net · csmailto | Medium5.0 | — | 2.0% | Aug 12, 2002 |
20Monitor | CVE-2002-0921No exploit | CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other concgiscript.net · csnews | Medium5.0 | — | 1.3% | Oct 4, 2002 |
20Monitor | CVE-2002-0920No exploit | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which ccgiscript.net · cspassword | Medium5.1 | — | 1.3% | Oct 4, 2002 |
- CVE-2002-074933Monitor
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.
HighCVSS 7.5Proof of conceptEPSS 11%cgiscript.net · csmailtoAug 12, 2002
- CVE-2002-092332Monitor
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2)
HighCVSS 7.5Proof of conceptEPSS 7%cgiscript.net · csnewsOct 4, 2002
- CVE-2002-091931Monitor
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title fi
HighCVSS 7.5Proof of conceptEPSS 3%cgiscript.net · cspasswordOct 4, 2002
- CVE-2002-075131Monitor
CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (
HighCVSS 7.5No exploitEPSS 3%cgiscript.net · csmailtoAug 12, 2002
- CVE-2002-091731Monitor
CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download th
HighCVSS 7.5No exploitEPSS 2%cgiscript.net · cspasswordOct 4, 2002
- CVE-2002-092430Monitor
CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text
HighCVSS 7.5No exploitEPSS 1%cgiscript.net · csnewsOct 4, 2002
- CVE-2002-091821Monitor
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the sc
MediumCVSS 5.0Proof of conceptEPSS 3%cgiscript.net · cspasswordOct 4, 2002
- CVE-2002-092221Monitor
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) defaul
MediumCVSS 5.0Proof of conceptEPSS 3%cgiscript.net · csnewsOct 4, 2002
- CVE-2004-066521Monitor
csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the we
MediumCVSS 5.0Proof of conceptEPSS 3%cgiscript.net · csfaqAug 6, 2004
- CVE-2002-175121Monitor
csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is pr
MediumCVSS 5.0No exploitEPSS 2%cgiscript.net · cslivesupportDec 31, 2002
- CVE-2002-075021Monitor
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment
MediumCVSS 5.0No exploitEPSS 2%cgiscript.net · csmailtoAug 12, 2002
- CVE-2002-075221Monitor
CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attack
MediumCVSS 5.0No exploitEPSS 2%cgiscript.net · csmailtoAug 12, 2002
- CVE-2002-092120Monitor
CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other con
MediumCVSS 5.0No exploitEPSS 1%cgiscript.net · csnewsOct 4, 2002
- CVE-2002-092020Monitor
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which c
MediumCVSS 5.1No exploitEPSS 1%cgiscript.net · cspasswordOct 4, 2002