Alias(es)CGI.csSearch.Command.Execution |
Release DateSep 11, 2006 |
Severityhigh |
ImpactAttackers can execute arbitrary perl commands on the victim system. |
DescriptionIt indicates an attempt to execute potentially damaging command via CGISCRIPT.NET csSearch.cgi program. csSearch is a website search script. Due to inadequate input checking, a remote attacker can execute arbitrary Perl code on a target system by sending it a specially-crafted message. |
Affected ProductsAny unprotected csSearch 2.3 or earlier version is vulnerable to the attack. |
Recommended ActionsApply appropriate patches or Upgrade the system to the latest non-vulnerable version. |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2002-0495 |
Reference/shttp://www.securityfocus.com/bid/4368 (BugTraq) |