This application requires Javascript for optimal performance.

CGI.CSLiveSupport.Remote.Command.Execution.B

Release Date

Jan 05, 2012

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

This indicates a possible exploit of a Remote Code Execution Vulnerability in csLiveSupport.cgi of CGIScript.net csLiveSupport.

An attacker may send a specially crafted HTTP request containing link to malicious perl code on setup parameter, which will be run on the affected server within the privilege of web server process. csLiveSupport is a script for providing live web support.

Affected Products

CGISCRIPT.NET csLiveSupport 1.0

Recommended Actions

Apply appropriate patch from the vendor.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2002-1751

Reference/s

http://www.securityfocus.com/bid/4450 (BugTraq)

Reference: VID-30557