CVE Vulnerabilities

CVE-1999-1053

Published: Sep 13, 1999 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

guestbook.pl cleanses user-inserted SSI commands by removing text between separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides –>.

Affected Software

Name Vendor Start Version End Version
Http_server Apache 1.3.9 (including) 1.3.9 (including)
Matt_wright_guestbook Matt_wright 2.3 (including) 2.3 (including)

References