CVE Vulnerabilities

CVE-1999-1053

Published: Sep 13, 1999 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

guestbook.pl cleanses user-inserted SSI commands by removing text between separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides –>.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache1.3.9 (including)1.3.9 (including)
Matt_wright_guestbookMatt_wright2.3 (including)2.3 (including)

References