about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , CGIScript.net csNews Header File Type Restriction Bypass Vulnerability


Title CGIScript.net csNews Header File Type Restriction Bypass Vulnerability
Published 2002-06-11-12:00AM
Updated 2002-06-11-10:56PM
Class Input Validation Error
CVE   CAN-2002-0923
Remote  Yes
Local  No
Credit  Discovery is credited to Steve Gustin <stegus1@yahoo.com>.
Vulnerable  CGISCRIPT.NET csNews Professional 1.0
Apache Software Foundation Apache 1.3.17
Apache Software Foundation Apache 1.3.18
Apache Software Foundation Apache 1.3.19
Apache Software Foundation Apache 1.3.20
Apache Software Foundation Apache 1.3.22
Apache Software Foundation Apache 1.3.23
Apache Software Foundation Apache 1.3.24
CGISCRIPT.NET csNews 1.0
Not Vulnerable  
Code   The following sample exploit has been contributed by Steve Gustin <stegus1@yahoo.com>.

javascript:alert(document.form1.pheader.value='setup.cgi');
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 12:08:04 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Animalsex. www.lexsen www.worlds ww89sexy.c www.gzdo.c trishbathi maxcpm.inf adduser taobaokid. Sabdrimer NetAddAlte 200 /compo www.chinav Crack Data sexy aks news for c war%2 conv 72747.cn Movex Www.Bollyw www.bdcsdz Aishwaryas www.dao198 maxcpm.inf apache2.2 Courier im microsoft www.szsfa. gypsys free flash Boobs imag Bhuvaneshv comic.i608 news for c Spotaudito airdeccan pooping gi wwww.xxxx. Girl12 t792t Www.pussys life insur fear hydrocodon PHP 4.0 admin hash FREE SEX mambo Remo dina and h Invision P