vendor:
guestbook.pl
by:
patrick
N/A
CVSS
N/A
Arbitrary Command Execution
Unknown
CWE
Product Name: guestbook.pl
Affected Version From: v2.3.1
Affected Version To: v2.3.1
Patch Exists: NO
Related CWE: 1999-1053
CPE: Unknown
Platforms Tested: unix, win, linux
1999
Matt Wright guestbook.pl Arbitrary Command Execution
The Matt Wright guestbook.pl <= v2.3.1 CGI script contains a flaw that may allow arbitrary command execution. The vulnerability requires that HTML posting is enabled in the guestbook.pl script, and that the web server must have the Server-Side Include (SSI) script handler enabled for the '.html' file type. By combining the script weakness with non-default server configuration, it is possible to exploit this vulnerability successfully.
Mitigation:
Unknown