Cgiwrap
Vendor:
First CVE: Jul 22, 2001 · Active for 25 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cgiwrap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2001
25 years ago
Most Recent CVE
Jun 25, 2008
6,603 days ago
CVE Severity & Scoring
Cgiwrap5 CVEs
60%
40%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0987HIGH Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into | Jul 22, 2001 | 7.5 | 31 | NO | YES |
CVE-2005-3254HIGH The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attac | Oct 18, 2005 | 10.0 | 25 | NO | NO |
CVE-2006-0767MEDIUM CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information. | Feb 18, 2006 | 5.0 | 15 | NO | NO |
CVE-2005-3255MEDIUM The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain se | Oct 18, 2005 | 5.0 | 15 | NO | NO |
CVE-2008-2852MEDIUM Cross-site scripting (XSS) vulnerability in CGIWrap before 4.1, when an Internet Explorer based browser is used, allows remote attackers to inject arbitrary web script or HTML via | Jun 25, 2008 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Cgiwrap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0 | 1 | 4.3 | 1.3% | 0 | 0 |
| 3.9 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.8_rc1 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.8 | 2 | 7.5 | 2.1% | 0 | 0 |
| 3.7.1 | 1 | 10.0 | 2.6% | 0 | 0 |
| 3.7 | 3 | 6.4 | 1.8% | 0 | 0 |
| 3.6_beta8 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta7 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta6 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta5 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta4 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta3 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta2 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6_beta1 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.6.5 | 1 | 10.0 | 2.6% | 0 | 0 |
| 3.6.4 | 3 | 6.4 | 1.8% | 0 | 0 |
| 3.6.3 | 3 | 6.4 | 1.8% | 0 | 0 |
| 3.6.2 | 3 | 6.4 | 1.8% | 0 | 0 |
| 3.6.10 | 1 | 4.3 | 1.3% | 0 | 0 |
| 3.6.1 | 3 | 6.4 | 1.8% | 0 | 0 |