vendor:
libwww-perl
by:
Infam0us Gr0up - Securiti Research
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: libwww-perl
Affected Version From: libwww-perl-5.76
Affected Version To: libwww-perl-5.76
Patch Exists: Yes
Related CWE: N/A
CPE: libwww-perl
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000 SP4
Unknown
Intruder Command Execution DOS Exploit
This exploit is a denial of service attack that uses the libwww-perl library to delete a file on a remote Windows 2000 SP4 system. It connects to the target system, creates malicious pages, opens the CDRom drive of the victim, and then deletes the specified file. The exploit was tested on Windows 2000 SP4 (Win NT).
Mitigation:
Ensure that the libwww-perl library is up to date and that all systems are running the latest security patches.