7.5
CVSSv2

CVE-2004-1782

Published: 31/12/2004 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

athenareg.php in Athena Web Registration allows remote malicious users to execute arbitrary commands via shell metacharacters in the pass parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

david maciejak athena web registration

Exploits

source: wwwsecurityfocuscom/bid/9349/info A problem has been reported in the handling of user-supplied input by the Athena Web Registration scripts Because of this, it may be possible for an attacker to gain unauthorized access to a vulnerable system wwwexamplecom/athenaregphp?pass=%20;whoami ...