Korean
<< Back
VID 21027
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The "cgitest.exe" CGI program is installed in the relevant web server. There is a buffer overrun in the "cgitest.exe" CGI program, which will allow anyone to execute arbitrary commands with the privileges of the http daemon (root or nobody).

* References:
http://www.securityfocus.com/bid/5706
http://www.iss.net/security_center/static/10102.php
Recommendation Remove "cgitest.exe" file from /cgi-bin directory.
Related URL CVE-2002-2146 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)