This application requires Javascript for optimal performance.

CGI.CSGuestbook.Remote.Code.Execution

Release Date

Dec 24, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

It indicates a possible attempt to exploit a Remote Code Execution vulnerability in csGuestbook.cgi of CGIScript.net CSGuestbook.

An attacker may send a specially crafted HTTP request containing link to malicious perl code on setup parameter which will be run on the affected server with privilege of web server process. csGuestbook is web guestbook software.

Affected Products

CGISCRIPT.NET csGuestbook 1.0

Recommended Actions

Apply appropriate patch from the vendor.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2002-1750

Reference/s

http://www.securityfocus.com/bid/4448 (BugTraq)

Reference: VID-30410