20020529 CGIscript.net - csPassword.cgi - Multiple Vulnerabilitiesmailing list
http://online.securityfocus.com/archive/1/274727 CVE-2002-0919
CGIScript.net - 'csPassword.cgi' 1.0 Information Disclosure
Record summary
CVE-2002-0919 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCGIScript.net - 'csPassword.cgi' 1.0 Information DisclosureExploitDB exploitby Steve GustinNot analyzed1 file
ExploitDBCGIScript.net - 'csPassword.cgi' 1.0 HTAccess File ModificationExploitDB exploitby Steve GustinNot analyzed1 file
References
4cgiscript-cspassword-htaccess-modification(9222)vdb entry
http://www.iss.net/security_center/static/9222.php 4888vdb entry
http://www.securityfocus.com/bid/4888 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0919