CVE detail
CVE-1999-1053 — CVE-1999-1053
Published 1999-09-13 · Modified 2026-06-16 · Vendor apache · Product http_server · Source nvd
UNKNOWN
severity
CVSS-derived band
0.8520
EPSS probability
exploitation probability, 30d
100.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References