vendor:
WebAPP
by:
Nikyt0x
9,3
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: WebAPP
Affected Version From: 0.9.9.2.1
Affected Version To: 0.9.9.2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:webapp:webapp:0.9.9.2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2004
WebAPP v0.9.9.2.1 Remote Command Execution Exploit
This exploit allows an attacker to execute arbitrary commands on a vulnerable WebAPP v0.9.9.2.1 installation. The vulnerability exists due to insufficient sanitization of user-supplied input to the 'cmd' parameter in the 'apage.cgi' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious commands to the vulnerable server. Successful exploitation of this vulnerability can result in arbitrary code execution on the vulnerable server.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to apply the patch as soon as possible.