Description
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Igor Dobrovitski · perlremotecgi
https://www.exploit-db.com/exploits/20914
Scores
EPSS
0.0214
EPSS Percentile
84.3%
Details
Status
published
Products (2)
cgicentral/webstore_400
4.14
cgicentral/webstore_400cs
4.14
Published
Jun 12, 2001
Tracked Since
Feb 18, 2026