Vulnerability Name:

CVE-2002-0922 (CCN-9332)

Assigned:2002-06-11
Published:2002-06-11
Updated:2008-09-05
Summary:CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: BUGTRAQ
Type: UNKNOWN
20020611 CGIscript.net - csNews.cgi - Multiple Vulnerabilities

Source: CCN
Type: BugTraq Mailing List, Tue Jun 11 2002 - 16:00:51 CDT
CGIscript.net - csNews.cgi - Multiple Vulnerabilities

Source: MITRE
Type: CNA
CVE-2002-0922

Source: CCN
Type: CGIScript.net Web site
CGI Script.net - Webmaster Resource Site - Free and Professional CGI Scripts and JavaScripts

Source: XF
Type: Vendor Advisory
cgiscript-csnews-file-disclosure(9332)

Source: XF
Type: Vendor Advisory
cgiscript-csnews-admin-access(9333)

Source: BID
Type: Vendor Advisory
4991

Source: CCN
Type: BID-4991
CGIScript.net CSNews Sensitive File Disclosure Vulnerability

Source: BID
Type: Exploit, Vendor Advisory
4993

Source: CCN
Type: BID-4993
CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability

Source: XF
Type: UNKNOWN
cgiscript-csnews-file-disclosure(9332)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cgiscript.net:csnews:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:cgiscript.net:csnews:1.0_professional:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2002-0922 (CCN-9333)

    Assigned:2002-06-11
    Published:2002-06-11
    Updated:2008-09-05
    Summary:CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.
    CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): Low
    Availibility (A): Low
    CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
    Exploitability Metrics:Access Vector (AV): Network
    Access Complexity (AC): Low
    Authentication (Au): None
    Impact Metrics:Confidentiality (C): Partial
    Integrity (I): None
    Availibility (A): None
    7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
    Exploitability Metrics:Access Vector (AV): Network
    Access Complexity (AC): Low
    Athentication (Au): None
    Impact Metrics:Confidentiality (C): Partial
    Integrity (I): Partial
    Availibility (A): Partial
    Vulnerability Type:CWE-Other
    Vulnerability Consequences:Gain Access
    References:Source: CCN
    Type: BugTraq Mailing List, Tue Jun 11 2002 - 16:00:51 CDT
    CGIscript.net - csNews.cgi - Multiple Vulnerabilities

    Source: MITRE
    Type: CNA
    CVE-2002-0922

    Source: MITRE
    Type: CNA
    CVE-2002-0923

    Source: CCN
    Type: CGIScript.net Web site
    CGI Script.net - Webmaster Resource Site - Free and Professional CGI Scripts and JavaScripts

    Source: CCN
    Type: OSVDB ID: 8134
    CGIScript.net csNews.cgi Advanced Settings Multiple Parameter Arbitrary File Retrieval

    Source: CCN
    Type: BID-4991
    CGIScript.net CSNews Sensitive File Disclosure Vulnerability

    Source: CCN
    Type: BID-4993
    CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability

    Source: CCN
    Type: BID-4994
    CGIScript.net csNews Header File Type Restriction Bypass Vulnerability

    Source: XF
    Type: UNKNOWN
    cgiscript-csnews-admin-access(9333)

    BACK
    cgiscript.net csnews 1.0
    cgiscript.net csnews 1.0_professional