CGI Rescue develops a portfolio of web-facing applications including form handlers, shopping carts, webform tools, and bulletin-board software, products that typically sit at the intersection of user input and dynamic HTML generation. The recurring vulnerability signal centers on web-layer input-handling weaknesses, particularly cross-site scripting and improper input validation, which reflect the exposure inherent to CGI-based web applications. Current exploitation activity and vulnerability severity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cgi Rescue over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2962HIGH CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vectors. | Jun 13, 2015 | 7.5 | 20 | NO | NO |
CVE-2007-0565HIGH CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors. | Jan 30, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-2943HIGH Unspecified vulnerability in CGI-RESCUE WebFORM 4.1 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for thi | Jun 12, 2006 | 7.5 | 19 | NO | NO |
CVE-2009-1590MEDIUM Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipients via a web form. | May 8, 2009 | 5.0 | 17 | NO | NO |
CVE-2008-5723MEDIUM Directory traversal vulnerability in CGI RESCUE KanniBBS2000 (aka KanniBBS2000i, MiniBBS2000, and MiniBBS2000i) before 1.03 allows remote attackers to read arbitrary files via unsp | Dec 26, 2008 | 5.0 | 16 | NO | NO |
CVE-2009-1591MEDIUM CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response | May 8, 2009 | 4.3 | 15 | NO | NO |
CVE-2009-1589MEDIUM Unspecified vulnerability in CGI RESCUE MiniBBS22 before 1.01 allows remote attackers to send email to arbitrary recipients via unknown vectors. | May 8, 2009 | 5.0 | 15 | NO | NO |
CVE-2007-4655MEDIUM Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arb | Sep 4, 2007 | 5.0 | 15 | NO | NO |
CVE-2006-4344MEDIUM CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) before 8.3 allows remote attackers to spoof e-mails and inject e-mail headers via unspecified vectors in (1) mail | Aug 24, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2944MEDIUM Unspecified vulnerability in CGI-RESCUE FORM2MAIL 1.21 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for | Jun 12, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cgi Rescue.
Media articles that mention a CVE ID that affects a product developed by Cgi Rescue — matched by CVE ID, not by vendor name.