Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-2420

EPSS 8.75% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-2420

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Super Site Searcher远程可执行任意命令漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Super Site Searcher是一款基于Web的搜索引擎系统。 Super Site Searcher没有正确过滤用户提交的输入,远程攻击者可以利用这个漏洞以WEB权限在系统上执行任意命令。 Super Site Searcher中的site_searcher.cgi脚本没有充分过滤用户提交给查询参数的转义字符,通过提交包含如"|"SHELL转义字符的任意命令,可导致命令直接传递给SHELL以Web权限执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-2420

#POC DescriptionSource LinkShenlong Link
1The New Exploit there no available on metasploit framework !https://github.com/krdsploit/CVE-2002-2420POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-2420

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-11-01 · 55 CVEs total

CVE-2007-5776Blue-Collar Productions i-Gallery igallery.ASP 目录遍历漏洞
CVE-2007-5791Vonage Motorola VT 2142用户身份伪造漏洞
CVE-2007-5786GoSamba 多个远程文件包含漏洞
CVE-2007-5789Grandstream HandyTone-488 PSTN To VoIP适配器IP栈远程拒绝服务漏洞
CVE-2007-5788Grandstream HandyTone-488 PSTN-to-VoIP适配器远程溢出漏洞
CVE-2007-5787Micro Login System UserPWD.TXT 信息泄露漏洞
CVE-2007-5790Globe7 SIP软件电话弱口令混淆漏洞
CVE-2007-5779Gretech GOM Player GomWeb3.dll远程栈溢出漏洞
CVE-2007-5778Mobile Spy Insecure Password Storage 信息泄露漏洞
CVE-2007-5777Blue-Collar Blue-Collar Productions I-Gallery web根目录 权限许可和访问控制漏洞
CVE-2007-5780Teatro pub08_comments.php 远程文件包含漏洞
CVE-2007-5775BitDefender在线扫描器OScan.OCX ActiveX控件堆溢出漏洞
CVE-2007-5774Flatnuke3 文件管理模块index.php 信息泄露漏洞
CVE-2007-5773Flatnuke index.php 跨站请求伪造漏洞
CVE-2007-5772Flatnuke3 文件管理模块 未授权访问漏洞
CVE-2007-5771Flatnuke3 myforum%00 cookie 权限绕过漏洞
CVE-2007-5793多个IDS产品全角/半角Unicode编码检测漏报漏洞
CVE-2002-2425Sun AnswerBook2未认证管理脚本访问漏洞
CVE-2002-2424PHPReactor样式属性HTML注入漏洞
CVE-2002-2423Sendmail超长Ident日志记录欺骗漏洞

Showing top 20 of 55 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-2420

No comments yet


Leave a comment