CVE-1999-1053
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
- Affected products
- Apache
- Apache Http Server
- = 1.3.9
- Matt Wright Matt Wright Guestbook
- = 2.3
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 85.2% (100th percentile)
- NVD status
- Modified
- Published
- 2001-09-12
CVE-1999-1053 at NVD
6 known exploits for CVE-1999-1053
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-1999-1053-PoC
The Matt Wright Guestbook.pl - Arbitrary Command Execution (Metasploit)
Matt Wright guestbook.pl Arbitrary Command Execution
Matt Wright guestbook.pl Arbitrary Command Execution
The Matt Wright Guestbook.pl 2.3.1 - Server-Side Include
The Matt Wright Guestbook.pl 2.3.1 - Server-Side Include