CVE-2002-0922

CGIScript.net csNews.cgi - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0922. PoCs published by Steve Gustin.

AI-analyzed exploit summary The exploit describes an authentication bypass vulnerability in csNews CGI script where double URL-encoded metacharacters allow unauthorized access to administrative pages. No actual exploit code is provided, only example URLs demonstrating the vulnerability.

Description

CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Steve Gustin · textwebappscgi
https://www.exploit-db.com/exploits/21532

The exploit describes an authentication bypass vulnerability in csNews CGI script where double URL-encoded metacharacters allow unauthorized access to administrative pages. No actual exploit code is provided, only example URLs demonstrating the vulnerability.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: csNews (version not specified)
No auth needed
Prerequisites: Access to the csNews.cgi script
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4991
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9333.php
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9332.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4993
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-06/0091.html

Scores

EPSS 0.0324
EPSS Percentile 86.7%

Details

Status published
Products (2)
cgiscript.net/csnews 1.0
cgiscript.net/csnews 1.0_professional
Published Oct 04, 2002
Tracked Since Feb 18, 2026