CVE-2002-1868

dispair 0.1 and 0.2 - Remote Code Execution via Form Field Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1868. PoCs published by anonymous.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Dispair's CGI script by passing malicious input via the 'view' parameter, which is executed by the Perl open() function. The provided URL demonstrates arbitrary command execution (e.g., /usr/bin/id).

Description

Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textwebappscgi
https://www.exploit-db.com/exploits/21679

This exploit leverages a command injection vulnerability in Dispair's CGI script by passing malicious input via the 'view' parameter, which is executed by the Perl open() function. The provided URL demonstrates arbitrary command execution (e.g., /usr/bin/id).

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Dispair (version not specified)
No auth needed
Prerequisites: Access to the target's CGI script (dispair.cgi)
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5392

Scores

EPSS 0.0544
EPSS Percentile 91.9%

Details

Status published
Products (2)
daniel_stenberg/dispair 0.1
daniel_stenberg/dispair 0.2
Published Dec 31, 2002
Tracked Since Feb 18, 2026