CVE
- Id
- 1033
- CVE No.
- CVE-1999-1053
- Status
- Candidate
- Description
- guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
- Phase
- Proposed (20010912)
- Votes
- MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall
- Comments
- Frech> XF:guestbook-cgi-command-execution(7783)