Leif M. Wright's vulnerability profile centers on a collection of small web-based utilities and form-handling scripts, including a web blog platform, ad-serving CGI, form processors, guestbook, and mail utilities that were distributed during the early web era. These components have frequently acquired public exploit code and reflect the broad category of "other" weaknesses typical of legacy or minimally validated web scripting. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leif M. Wright over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0025HIGH ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter. | Feb 12, 2001 | 10.0 | 47 | NO | YES |
CVE-2001-0024HIGH simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter. | Feb 12, 2001 | 10.0 | 43 | NO | YES |
CVE-2001-0023HIGH everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. | Feb 12, 2001 | 10.0 | 42 | NO | YES |
CVE-2001-0022HIGH simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter. | Feb 12, 2001 | 10.0 | 41 | NO | YES |
CVE-2004-2347HIGH blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile reque | Dec 31, 2004 | 7.5 | 32 | NO | YES |
CVE-2004-2127MEDIUM Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable. | Jan 20, 2004 | 5.0 | 23 | NO | YES |
CVE-2005-1351HIGH The ad.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | May 2, 2005 | 7.5 | 22 | NO | NO |
CVE-2006-0844HIGH Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, proba | Feb 22, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-0845MEDIUM Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path | Feb 22, 2006 | 6.5 | 18 | NO | NO |
CVE-2005-1350MEDIUM The ad.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | May 2, 2005 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leif M. Wright.
Media articles that mention a CVE ID that affects a product developed by Leif M. Wright — matched by CVE ID, not by vendor name.