vendor:
hints.cgi
by:
MadSheep
9,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: hints.cgi
Affected Version From: all
Affected Version To: all
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
WebHints Software hints.cgi Remote Command Execution Vulnerability
A remote command execution vulnerability exists in WebHints Software hints.cgi, which is a web-based application. The vulnerability allows an attacker to execute arbitrary commands on the vulnerable system. The vulnerability is due to insufficient input validation of user-supplied data. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious code to the vulnerable system. The malicious code will be executed on the vulnerable system, allowing the attacker to gain access to the system.
Mitigation:
Input validation should be performed on all user-supplied data to ensure that it is valid and does not contain malicious code. Additionally, the application should be kept up to date with the latest security patches.