VulnerabilityModified
CVE-2002-0495
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
HIGH 10.0EPSS 13.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 13.34% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cgiscript/cssearch professional
- Source
- cve@mitre.org
References
- http://www.cgiscript.net/cgi-script/csNews/csNews.cgi?database=cgi.db&command=viewone&id=7Product
- http://www.iss.net/security_center/static/8636.phpBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/264169Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/4368Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.cgiscript.net/cgi-script/csNews/csNews.cgi?database=cgi.db&command=viewone&id=7Product
- http://www.iss.net/security_center/static/8636.phpBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/264169Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/4368Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.