7.5
CVSSv2

CVE-2004-2347

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote malicious users to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests.

Vulnerable Product Search on Vulmon Subscribe to Product

leif m. wright web blog 1.1

leif m. wright web blog 1.1.5

Exploits

source: wwwsecurityfocuscom/bid/9539/info Web Blog has been reported to be prone to a vulnerability that may permit remote attackers to execute arbitrary commands in the context of the hosting web server This is due to insufficient sanitization of shell metacharacters from variables which will be used as an argument to a function that in ...