peter bassill · operator
$ cve CVE-2002-1410 JSON

CVE-2002-1410 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.81% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-11
Last modified2026-06-16

Affected (2)

VendorProduct
ben chiversben chivers guestbook
easy scripts archiveeasy guestbook

Public exploits

SourceTitleDate
exploit-dbBen Chivers Easy Guestbook 1.0 - Administrative Access2002-07-29

References

→ the Explorer  ·  watch your stack  ·  NVD