7.5
CVSSv2

CVE-2005-0689

Published: 07/03/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

includer.cgi in The Includer allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

jimmy the includer 1.0

jimmy the includer 1.1

Exploits

#!/usr/bin/perl # # [K-C0d3r] Includercgi 10 remote command execution [K-C0d3r] # # C0d3d By K-C0d3r, a wwwx0n3-h4ckorg friend! # # I think the bug was discovered by Francisco Alisson # # Greetz to: mZ, CorryL, Expanders, SiNaPsE, off, rikky, milw0rm # # F**K o*f to all RxBot kiddies as e*****t, G***n, d***b # ############################### ...
Remote Command Execution on: Example I: wwwhost-vulnerablecom/includercgi?|id| Example II: wwwhost-vulnerablecom/includercgi?template=|id| # milw0rmcom [2005-03-07] ...
#!/usr/bin/perl ############################################################ # Target - The In ...