Vulnerability Name: | CVE-2002-0922 (CCN-9332) | ||||||||
Assigned: | 2002-06-11 | ||||||||
Published: | 2002-06-11 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20020611 CGIscript.net - csNews.cgi - Multiple Vulnerabilities Source: CCN Type: BugTraq Mailing List, Tue Jun 11 2002 - 16:00:51 CDT CGIscript.net - csNews.cgi - Multiple Vulnerabilities Source: MITRE Type: CNA CVE-2002-0922 Source: CCN Type: CGIScript.net Web site CGI Script.net - Webmaster Resource Site - Free and Professional CGI Scripts and JavaScripts Source: XF Type: Vendor Advisory cgiscript-csnews-file-disclosure(9332) Source: XF Type: Vendor Advisory cgiscript-csnews-admin-access(9333) Source: BID Type: Vendor Advisory 4991 Source: CCN Type: BID-4991 CGIScript.net CSNews Sensitive File Disclosure Vulnerability Source: BID Type: Exploit, Vendor Advisory 4993 Source: CCN Type: BID-4993 CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability Source: XF Type: UNKNOWN cgiscript-csnews-file-disclosure(9332) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2002-0922 (CCN-9333) | ||||||||
Assigned: | 2002-06-11 | ||||||||
Published: | 2002-06-11 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Jun 11 2002 - 16:00:51 CDT CGIscript.net - csNews.cgi - Multiple Vulnerabilities Source: MITRE Type: CNA CVE-2002-0922 Source: MITRE Type: CNA CVE-2002-0923 Source: CCN Type: CGIScript.net Web site CGI Script.net - Webmaster Resource Site - Free and Professional CGI Scripts and JavaScripts Source: CCN Type: OSVDB ID: 8134 CGIScript.net csNews.cgi Advanced Settings Multiple Parameter Arbitrary File Retrieval Source: CCN Type: BID-4991 CGIScript.net CSNews Sensitive File Disclosure Vulnerability Source: CCN Type: BID-4993 CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability Source: CCN Type: BID-4994 CGIScript.net csNews Header File Type Restriction Bypass Vulnerability Source: XF Type: UNKNOWN cgiscript-csnews-admin-access(9333) | ||||||||
BACK |