CVE-2002-1410 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)
Patch early
A public exploit exists.
Description
Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.81% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-04-11 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| ben chivers | ben chivers guestbook |
| easy scripts archive | easy guestbook |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ben Chivers Easy Guestbook 1.0 - Administrative Access | 2002-07-29 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0356.html
- http://www.iss.net/security_center/static/9697.php
- http://www.securityfocus.com/bid/5341
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0356.html
- http://www.iss.net/security_center/static/9697.php
- http://www.securityfocus.com/bid/5341
→ the Explorer · watch your stack · NVD