10
CVSSv2

CVE-2001-0023

Published: 12/02/2001 Updated: 19/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

everythingform.cgi CGI program by Leif Wright allows remote malicious users to execute arbitrary commands via shell metacharacters in the config parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

leif m. wright everythingform.cgi 2.0

Exploits

source: wwwsecurityfocuscom/bid/2101/info An input validation vulnerability exists in Leif M Wright's everythingcgi, a Perl-based form design tool The script fails to properly filter shell commands from user-supplied input to the 'config' field As a result, the script can be made to run arbitrary shell commands with the privilege of ...