vendor:
Baby Web Server
by:
Infam0us Gr0up - Securiti Research
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Baby Web Server
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000 SP4
2005
Baby Web Server Command Validation Exploit
This is a Perl script that exploits a command validation vulnerability in the Baby Web Server. It allows an attacker to execute arbitrary commands on the server. The script takes three arguments: the target IP address, the input file containing the command to execute, and the path of the file on the server.
Mitigation:
The vendor should release a patch to fix the command validation vulnerability. In the meantime, users should restrict access to the Baby Web Server and apply strong input validation to prevent command injection attacks.