header-logo
Suggest Exploit
vendor:
fastreader
by:
Unknown
7.5
CVSS
HIGH
Remote command-execution
Unknown
CWE
Product Name: fastreader
Affected Version From: 1.0.8
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: fastreader
Metasploit:
Other Scripts:
Platforms Tested: Unknown
Unknown

fastreader remote command-execution vulnerability

The fastreader application fails to sanitize user-supplied input, allowing an attacker to execute arbitrary commands in the context of the affected application.

Mitigation:

Unknown
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/58450/info

fastreader is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.

fastreader 1.0.8 is affected; other versions may also be vulnerable. 

The following example URI is available:

http://www.g;id;.com