CGIScript.net csPassword.CGI Information Disclosure Vulnerability
BID:4887
Info
CGIScript.net csPassword.CGI Information Disclosure Vulnerability
| Bugtraq ID: | 4887 |
| Class: | Unknown |
| CVE: |
CVE-2002-0918 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Credited to Steve Gustin <[email protected]>. |
| Vulnerable: |
CGISCRIPT.NET csPassword 1.0 |
| Not Vulnerable: | |
Exploit / POC
CGIScript.net csPassword.CGI Information Disclosure Vulnerability
The following proof of concept was provided:
http://target/csPassword.cgi?command=remove
This will cause csPassword to execute the remove() function. This function is not defined and thus will cause an error page to be displayed.
The following proof of concept was provided:
http://target/csPassword.cgi?command=remove
This will cause csPassword to execute the remove() function. This function is not defined and thus will cause an error page to be displayed.
Solution / Fix
CGIScript.net csPassword.CGI Information Disclosure Vulnerability
Solution:
Password protecting access to the csPassword.cgi program would effectively prevent unauthorized users from viewing the debugging information.
The vendor is aware of this problem; users are advised to contact the vendor for patch information.
Solution:
Password protecting access to the csPassword.cgi program would effectively prevent unauthorized users from viewing the debugging information.
The vendor is aware of this problem; users are advised to contact the vendor for patch information.