10
CVSSv2

CVE-2001-0022

Published: 12/02/2001 Updated: 19/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

simplestguest.cgi CGI program by Leif Wright allows remote malicious users to execute arbitrary commands via shell metacharacters in the guestbook parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

leif m. wright simplestguest.cgi 2.0

Exploits

source: wwwsecurityfocuscom/bid/2106/info A vulnerabiliy exists in Leif M Wright's simplestguestcgi, a script designed to coordinate guestbook submissions from website visitors An insecure call to the open() function leads to a failure to properly filter shell metacharacters from user supplied input As a result, it is possible for an ...