apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote malicious users to execute arbitrary commands via shell metacharacters in the f parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
web-app.org webapp 0.9.9.2.1 |
||
web-app.org webapp 0.9.9.2 |
||
web-app.org webapp 0.9.9 |