Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-1365

Опубликовано: 31 дек. 2003
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:perl:cgi_lite:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00528
Низкий

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.

EPSS

Процентиль: 67%
0.00528
Низкий

5 Medium

CVSS2

Дефекты

CWE-20