20020612 SSI & CSS execution in MakeBook 2.2mailing list
http://archives.neohapsis.com/archives/bugtraq/2002-06/0094.html CVE-2002-0948
MakeBook 2.2 - Form Field Input Validation
Record summary
CVE-2002-0948 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMakeBook 2.2 - Form Field Input ValidationExploitDB exploitby b0ilerNot analyzed1 file
References
720020613 Re: SSI & CSS execution in MakeBook 2.2mailing list
http://cert.uni-stuttgart.de/archive/bugtraq/2002/06/msg00135.html makebook-name-field-validation(9356)vdb entry
http://www.iss.net/security_center/static/9356.php linguistic-funland.comConfirmation
http://www.linguistic-funland.com/scripts/MakeBook/makebook.script 4996vdb entry
http://www.securityfocus.com/bid/4996 tesol.netConfirmation
http://www.tesol.net/scriptmail.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0948