vendor:
Includer CGI
by:
Network Security Team - nst.void.ru
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: Includer CGI
Affected Version From: 1
Affected Version To: 1
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
Includer CGI <= 1.0 Remote Command Execution
This exploit allows an attacker to execute arbitrary commands on the target system by exploiting a vulnerability in the Includer CGI <= 1.0. The vulnerability is due to the improper use of the 'Open' function. By sending a specially crafted request, an attacker can inject arbitrary commands and execute them on the target system.
Mitigation:
It is recommended to update to the latest version of the Includer CGI to mitigate this vulnerability. Additionally, proper input validation and sanitization should be implemented to prevent command injection attacks.