CVE

Id
1033  
CVE No.
CVE-1999-1053  
Status
Candidate  
Description
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".  
Phase
Proposed (20010912)  
Votes
MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  
Comments
Frech> XF:guestbook-cgi-command-execution(7783)