CGIScript.net Information Disclosure Vulnerability
BID:4764
Info
CGIScript.net Information Disclosure Vulnerability
| Bugtraq ID: | 4764 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2002 12:00AM |
| Updated: | May 17 2002 12:00AM |
| Credit: | Discovered by Steve Gustin <[email protected]>. |
| Vulnerable: |
CGISCRIPT.NET csUpload 1.0 CGISCRIPT.NET csRandomText 1.0 CGISCRIPT.NET csNews Professional 1.0 CGISCRIPT.NET csNews 1.0 CGISCRIPT.NET csMailto CGISCRIPT.NET csIncludes 1.0 CGISCRIPT.NET csGrid 1.0 CGISCRIPT.NET csFileshare 1.0 CGISCRIPT.NET csFiler 1.0 CGISCRIPT.NET csFAQ 1.0 CGISCRIPT.NET csDownload 1.0 CGISCRIPT.NET csCreatePro 1.0 CGISCRIPT.NET csBanner 1.0 |
| Not Vulnerable: | |
Discussion
CGIScript.net Information Disclosure Vulnerability
CGIScript.net provides various webmaster related tools and is maintained by Mike Barone and Andy Angrick.
It is possible to cause numerous scripts provided by CGIScript.net to disclose sensitive system information.
The following is a list of cgi scripts that are susceptible to this issue:
csBanner.cgi
csCreatePro.cgi
CSDownload.cgi
csFAQ.cgi
CSFiler.cgi
CSFileshare.cgi
CSGrid.cgi
CSIncludes.cgi
CSMailto.cgi
CSNews.cgi
CSNews.cgi (pro version)
CSRandomText.cgi
CSUpload.cgi
Path, form input, and environment variable information is disclosed when a malformed POST request is submitted. This information may aid the attacker in making further attacks against the host.
CGIScript.net provides various webmaster related tools and is maintained by Mike Barone and Andy Angrick.
It is possible to cause numerous scripts provided by CGIScript.net to disclose sensitive system information.
The following is a list of cgi scripts that are susceptible to this issue:
csBanner.cgi
csCreatePro.cgi
CSDownload.cgi
csFAQ.cgi
CSFiler.cgi
CSFileshare.cgi
CSGrid.cgi
CSIncludes.cgi
CSMailto.cgi
CSNews.cgi
CSNews.cgi (pro version)
CSRandomText.cgi
CSUpload.cgi
Path, form input, and environment variable information is disclosed when a malformed POST request is submitted. This information may aid the attacker in making further attacks against the host.
Exploit / POC
CGIScript.net Information Disclosure Vulnerability
Steve Gustin <[email protected]> has provided the following exploit:
Steve Gustin <[email protected]> has provided the following exploit:
Solution / Fix
CGIScript.net Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CGIScript.net Information Disclosure Vulnerability
References:
References:
- CGISCRIPT.NET Homepage (CGISCRIPT.NET)