10
CVSSv2

CVE-2000-0690

Published: 20/10/2000 Updated: 10/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Auction Weaver CGI script 1.02 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in the fromfile parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cgi script center auction weaver 1.02

cgi script center auction weaver 1.0

Exploits

source: wwwsecurityfocuscom/bid/1645/info CGI Script Center's Auction Weaver does not verify the validity of the value in the variable 'fromfile' Therefore it is possible to perform arbitrary commands on a remote system under the UID of the http daemon by altering the variable 'fromfile' #!/usr/bin/perl -w ## Auction Weaver 102 / On ...