20020629 SSI & CSS execution in E-Guest (1.1) & ZAP Book (v1.0.3)mailing list
http://archives.neohapsis.com/archives/bugtraq/2002-06/0388.html CVE-2002-2376
E-Guest 1.1 - Server Side Include Arbitrary Command Execution
Record summary
CVE-2002-2376 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBE-Guest 1.1 - Server Side Include Arbitrary Command ExecutionExploitDB exploitby DownBloadNot analyzed1 file
References
6eguest-html-xss(9469)vdb entry
http://www.iss.net/security_center/static/9469.php eguest-ssi-command-execution(9470)vdb entry
http://www.iss.net/security_center/static/9470.php 5128vdb entry
http://www.securityfocus.com/bid/5128 5129vdb entry
http://www.securityfocus.com/bid/5129 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-2376