" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". "> ",separators,,which,allows,remote,attackers,to execute,arbitrary,commands,when,guestbook.pl,is,run,on,Apache,1.3.9 and,possibly,other,versions,,since,Apache,allows,other,closing sequences,besides,"-->". "> SecuritySpace - CVE-1999-1053
 
 
 Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-1999-1053
Description:guestbook.pl cleanses user-inserted SSI commands by removing text between "" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
Test IDs: 1.3.6.1.4.1.25623.1.0.10099  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-1999-1053
BugTraq ID: 776
http://www.securityfocus.com/bid/776
Bugtraq: 19991105 Guestbook.pl, sloppy SSI handling in Apache? (VD#2) (Google Search)
http://www.securityfocus.com/archive/1/33674
http://www.securityfocus.com/archive/82/27296
http://www.securityfocus.com/archive/82/27560




© 1998-2025 E-Soft Inc. All rights reserved.