vendor:
Home Web Server
by:
Guillaume Kaddouch
7.5
CVSS
HIGH
CGI Remote Code Execution
CWE
Product Name: Home Web Server
Affected Version From: 1.9.2001
Affected Version To: 1.9.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 SP1 Family x64 (FR)
2017
Home Web Server 1.9.1 build 164 – CGI Remote Code Execution
Home Web Server allows to call cgi programs via POST which are located into /cgi-bin folder. However by using a directory traversal, it is possible to run any executable being on the remote host.