CVE-2002-0923 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 6.98% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-10-04 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cgiscript.net | csnews |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CGIScript.net csNews 1.0 - Header File Type Restriction Bypass | 2002-06-11 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0091.html
- http://www.iss.net/security_center/static/9333.php
- http://www.securityfocus.com/bid/4994
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0091.html
- http://www.iss.net/security_center/static/9333.php
- http://www.securityfocus.com/bid/4994
→ the Explorer · watch your stack · NVD