CVE-1999-1053
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 85.20% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · matt wright/matt wright guestbook
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/33674Vendor Advisory
- http://www.securityfocus.com/archive/82/27296Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/82/27560Vendor Advisory
- http://www.securityfocus.com/bid/776Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/33674Vendor Advisory
- http://www.securityfocus.com/archive/82/27296Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/82/27560Vendor Advisory
- http://www.securityfocus.com/bid/776Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.