vendor:
by:
SegmentationFault Group
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Remote Command Execution Vulnerability In Web_store.cgi
This exploit allows remote attackers to execute arbitrary commands via a vulnerable Web_store.cgi script. The exploit requires the ability to write to the /tmp directory.
Mitigation:
To mitigate this vulnerability, ensure that the Web_store.cgi script does not allow arbitrary command execution and restrict write permissions to the /tmp directory.