Записи cgiscript.net
14 опубликованных записей вендора cgiscript.net.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2002-0749Proof of concept | CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.cgiscript.net · csmailto | Высокая7,5 | — | 11,0 % | 12 авг. 2002 г. |
32Наблюдать | CVE-2002-0923Proof of concept | CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2)cgiscript.net · csnews | Высокая7,5 | — | 7,0 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2002-0919Proof of concept | CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title ficgiscript.net · cspassword | Высокая7,5 | — | 3,1 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2002-0751Эксплойта нет | CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (cgiscript.net · csmailto | Высокая7,5 | — | 2,7 % | 12 авг. 2002 г. |
31Наблюдать | CVE-2002-0917Эксплойта нет | CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download thcgiscript.net · cspassword | Высокая7,5 | — | 2,4 % | 4 окт. 2002 г. |
30Наблюдать | CVE-2002-0924Эксплойта нет | CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text cgiscript.net · csnews | Высокая7,5 | — | 1,4 % | 4 окт. 2002 г. |
21Наблюдать | CVE-2002-0918Proof of concept | CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the sccgiscript.net · cspassword | Средняя5,0 | — | 3,5 % | 4 окт. 2002 г. |
21Наблюдать | CVE-2002-0922Proof of concept | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) defaulcgiscript.net · csnews | Средняя5,0 | — | 3,2 % | 4 окт. 2002 г. |
21Наблюдать | CVE-2004-0665Proof of concept | csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the wecgiscript.net · csfaq | Средняя5,0 | — | 2,9 % | 6 авг. 2004 г. |
21Наблюдать | CVE-2002-1751Эксплойта нет | csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is prcgiscript.net · cslivesupport | Средняя5,0 | — | 2,1 % | 31 дек. 2002 г. |
21Наблюдать | CVE-2002-0750Эксплойта нет | CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment cgiscript.net · csmailto | Средняя5,0 | — | 2,1 % | 12 авг. 2002 г. |
21Наблюдать | CVE-2002-0752Эксплойта нет | CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackcgiscript.net · csmailto | Средняя5,0 | — | 2,0 % | 12 авг. 2002 г. |
20Наблюдать | CVE-2002-0921Эксплойта нет | CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other concgiscript.net · csnews | Средняя5,0 | — | 1,3 % | 4 окт. 2002 г. |
20Наблюдать | CVE-2002-0920Эксплойта нет | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which ccgiscript.net · cspassword | Средняя5,1 | — | 1,3 % | 4 окт. 2002 г. |
- CVE-2002-074933Наблюдать
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.
ВысокаяCVSS 7,5Proof of conceptEPSS 11 %cgiscript.net · csmailto12 авг. 2002 г.
- CVE-2002-092332Наблюдать
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2)
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %cgiscript.net · csnews4 окт. 2002 г.
- CVE-2002-091931Наблюдать
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title fi
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %cgiscript.net · cspassword4 окт. 2002 г.
- CVE-2002-075131Наблюдать
CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cgiscript.net · csmailto12 авг. 2002 г.
- CVE-2002-091731Наблюдать
CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download th
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cgiscript.net · cspassword4 окт. 2002 г.
- CVE-2002-092430Наблюдать
CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cgiscript.net · csnews4 окт. 2002 г.
- CVE-2002-091821Наблюдать
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the sc
СредняяCVSS 5,0Proof of conceptEPSS 3 %cgiscript.net · cspassword4 окт. 2002 г.
- CVE-2002-092221Наблюдать
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) defaul
СредняяCVSS 5,0Proof of conceptEPSS 3 %cgiscript.net · csnews4 окт. 2002 г.
- CVE-2004-066521Наблюдать
csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the we
СредняяCVSS 5,0Proof of conceptEPSS 3 %cgiscript.net · csfaq6 авг. 2004 г.
- CVE-2002-175121Наблюдать
csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is pr
СредняяCVSS 5,0Эксплойта нетEPSS 2 %cgiscript.net · cslivesupport31 дек. 2002 г.
- CVE-2002-075021Наблюдать
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment
СредняяCVSS 5,0Эксплойта нетEPSS 2 %cgiscript.net · csmailto12 авг. 2002 г.
- CVE-2002-075221Наблюдать
CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attack
СредняяCVSS 5,0Эксплойта нетEPSS 2 %cgiscript.net · csmailto12 авг. 2002 г.
- CVE-2002-092120Наблюдать
CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other con
СредняяCVSS 5,0Эксплойта нетEPSS 1 %cgiscript.net · csnews4 окт. 2002 г.
- CVE-2002-092020Наблюдать
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which c
СредняяCVSS 5,1Эксплойта нетEPSS 1 %cgiscript.net · cspassword4 окт. 2002 г.