7.5
CVSSv2

CVE-2001-0307

Published: 03/05/2001 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Bajie HTTP JServer 0.78, and other versions prior to 0.80, allows remote malicious users to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

Vulnerable Product Search on Vulmon Subscribe to Product

bajie java http server

Exploits

source: wwwsecurityfocuscom/bid/2389/info Requesting a specailly crafted URL containg arbitrary code, can be exected on a Unix system running Bajie Webserver Any arbitrary commands appended to a malicious URL after the ';' will be executed as an independent job target/bin/testtxt;%20[shell command] ...