CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the Advanced Settings capability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Csnews | Cgiscript.net | 1.0 (including) | 1.0 (including) |
Csnews | Cgiscript.net | 1.0_professional (including) | 1.0_professional (including) |