VulnerabilityModified
CVE-2002-1753
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
HIGH 7.5EPSS 32.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 32.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 32.20% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cgiscript/csnews professional
- Source
- cve@mitre.org
References
- http://cert.uni-stuttgart.de/archive/bugtraq/2002/04/msg00106.htmlBroken Link
- http://www.securityfocus.com/bid/4451Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8636Third Party Advisory, VDB Entry
- http://cert.uni-stuttgart.de/archive/bugtraq/2002/04/msg00106.htmlBroken Link
- http://www.securityfocus.com/bid/4451Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8636Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.