Record summary

CVE-2002-0923 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCGIScript.net csNews 1.0 - Header File Type Restriction BypassExploitDB exploitby Steve GustinNot analyzed1 file
ExploitDB

PoC details

References

4