Cgiscript.Net's vulnerability profile centers on a small family of web-based application services including mail, news, password management, FAQ, and live-support products, many deployed as legacy components in older web infrastructures. The vendor's disclosures frequently acquire public exploit code, reflecting the historical accessibility of these CGI-based applications to unauthenticated reconnaissance and testing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cgiscript.Net over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0749HIGH CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field. | Aug 12, 2002 | 7.5 | 39 | NO | YES |
CVE-2002-0923HIGH CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Set | Oct 4, 2002 | 7.5 | 31 | NO | YES |
CVE-2002-0919HIGH CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page. | Oct 4, 2002 | 7.5 | 29 | NO | YES |
CVE-2002-0917HIGH CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other | Oct 4, 2002 | 7.5 | 25 | NO | NO |
CVE-2004-0665MEDIUM csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message. | Aug 6, 2004 | 5.0 | 23 | NO | YES |
CVE-2002-0918MEDIUM CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attacker | Oct 4, 2002 | 5.0 | 23 | NO | YES |
CVE-2002-0922MEDIUM CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated us | Oct 4, 2002 | 5.0 | 23 | NO | YES |
CVE-2002-0751HIGH CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form- | Aug 12, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-0924HIGH CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capabi | Oct 4, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-1751MEDIUM csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | Dec 31, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cgiscript.Net.
Media articles that mention a CVE ID that affects a product developed by Cgiscript.Net — matched by CVE ID, not by vendor name.