peter bassill · operator
$ cve CVE-2002-0495 JSON

CVE-2002-0495 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 13.3% (pctl 96)

Patch early

A public exploit exists.

Description

csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS13.34% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2002-08-12
Last modified2026-06-16

Affected (1)

VendorProduct
cgiscriptcssearch professional

Public exploits

SourceTitleDate
exploit-dbCSSearch 2.3 - Remote Command Execution2002-03-26

References

→ the Explorer  ·  watch your stack  ·  NVD