10
CVSSv2

CVE-2002-1868

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Dispair 0.1 and 0.2 allows remote malicious users to execute arbitrary shell commands via certain form fields.

Vulnerable Product Search on Vulmon Subscribe to Product

daniel stenberg dispair 0.1

daniel stenberg dispair 0.2

Exploits

source: wwwsecurityfocuscom/bid/5392/info Dispair fails to sufficiently validate user-supplied input before it is passed to the shell via the Perl open() function Remote attackers may potentially exploit this issue to execute arbitrary commands on the underlying shell with the privileges of the webserver process target/cgi-bin/d ...