Vulnerability Description
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 1.3.9 |
| Matt Wright | Matt Wright Guestbook | 2.3 |
References
- http://www.securityfocus.com/archive/1/33674Vendor Advisory
- http://www.securityfocus.com/archive/82/27296ExploitVendor Advisory
- http://www.securityfocus.com/archive/82/27560Vendor Advisory
- http://www.securityfocus.com/bid/776ExploitPatchVendor Advisory
- http://www.securityfocus.com/archive/1/33674Vendor Advisory
- http://www.securityfocus.com/archive/82/27296ExploitVendor Advisory
- http://www.securityfocus.com/archive/82/27560Vendor Advisory
- http://www.securityfocus.com/bid/776ExploitPatchVendor Advisory
FAQ
What is CVE-1999-1053?
CVE-1999-1053 is a vulnerability with a CVSS score of 7.5 (HIGH). guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1....
How severe is CVE-1999-1053?
CVE-1999-1053 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1053?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Matt Wright Matt Wright Guestbook.