vendor:
nostromo nhttpd
by:
RedTeam Pentesting GmbH
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: nostromo nhttpd
Affected Version From: prior to 1.9.4
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2012
nostromo nhttpd Remote Command Execution Vulnerability
nostromo nhttpd is prone to a remote command-execution vulnerability because it fails to properly validate user-supplied data. An attacker can exploit this issue to access arbitrary files and execute arbitrary commands with application-level privileges.
Mitigation:
Upgrade to the latest version of nostromo nhttpd (1.9.4 or later)