vendor:
Auction Weaver
by:
teleh0r
7.5
CVSS
HIGH
Arbitrary Command Execution
78
CWE
Product Name: Auction Weaver
Affected Version From: 01.02
Affected Version To: 01.02
Patch Exists: YES
Related CWE: N/A
CPE: a:cgi_script_center:auction_weaver
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2000
CGI Script Center’s Auction Weaver Arbitrary Command Execution
CGI Script Center's Auction Weaver does not verify the validity of the value in the variable 'fromfile'. Therefore it is possible to perform arbitrary commands on a remote system under the UID of the http daemon by altering the variable 'fromfile'.
Mitigation:
Verify the validity of the value in the variable 'fromfile'