Description
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Contact Form Builder Cross-Site Scripting (1.0)
WordPress Plugin CataBlog 'category' Parameter Cross-Site Scripting (1.6.2)
Oracle Database Server CVE-2009-1015 Vulnerability (CVE-2009-1015)
WordPress Plugin Custom Search by BestWebSoft Cross-Site Scripting (1.35)
Skipper Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-38580)