Korean
<< Back
VID 21321
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The MyServer Sample CGI math_sum.mscgi is vulnerable to a multiple remote vulnerabilities.
MyServer is a freely available Web server for Microsoft Windows and Linux-based platforms. MyServer version 0.6.2 and possibly other versions are vulnerable to multiple remote vulnerabilities in the 'math_sum.mscgi' example script. These flaws are due to a boundary condition error and a failure to properly sanitize user-supplied URI input. An attacker could exploit the boundary condition issue to execute arbitrary code on the affected computer with the privileges of the user that started the affected application. The input validation issue could be leveraged to carry out cross-site scripting attacks against the affected computer.

* Platforms Affected:
MyServer Project, MyServer 0.6.2
Linux Any version
Microsoft Windows Any version
Recommendation Remove the 'math_sum.mscgi' example script from the CGI-BIN directory.
Related URL (CVE)
Related URL 10831 (SecurityFocus)
Related URL (ISS)