HIGH · 7.5

CVE-2002-1410

Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of...

Vulnerability Description

Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Ben ChiversBen Chivers Guestbook1.0
Easy Scripts ArchiveEasy Guestbook1.0

References

FAQ

What is CVE-2002-1410?

CVE-2002-1410 is a vulnerability with a CVSS score of 7.5 (HIGH). Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of...

How severe is CVE-2002-1410?

CVE-2002-1410 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1410?

Check the references section above for vendor advisories and patch information. Affected products include: Ben Chivers Ben Chivers Guestbook, Easy Scripts Archive Easy Guestbook.