| VID |
21027 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The "cgitest.exe" CGI program is installed in the relevant web server. There is a buffer overrun in the "cgitest.exe" CGI program, which will allow anyone to execute arbitrary commands with the privileges of the http daemon (root or nobody).
* References: http://www.securityfocus.com/bid/5706 http://www.iss.net/security_center/static/10102.php |
| Recommendation |
Remove "cgitest.exe" file from /cgi-bin directory. |
| Related URL |
CVE-2002-2146 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|