Unrated severityNVD Advisory· Published Jul 17, 2001· Updated Apr 16, 2026
CVE-2001-1241
CVE-2001-1241
Description
Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.
Affected products
12cpe:2.3:a:steve_grimm:un-cgi:1.0:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:steve_grimm:un-cgi:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.7:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.8:*:*:*:*:*:*:*
- cpe:2.3:a:steve_grimm:un-cgi:1.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.iss.net/security_center/static/6847.phpnvdPatchVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2001-07/0287.htmlnvd
- archives.neohapsis.com/archives/bugtraq/2001-07/0349.htmlnvd
- www.midwinter.com/~koreth/uncgi-changes.htmlnvd
- www.midwinter.com/~koreth/uncgi.htmlnvd
- www.securityfocus.com/bid/3057nvd
News mentions
0No linked articles in our index yet.