vendor:
by:
Severino Honorato
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name:
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Priv8crew – ssh.D.Worm
This exploit allows an attacker to execute remote commands on a vulnerable server by exploiting a command injection vulnerability in the topic.php file. The attacker sends a crafted request to the server, which then downloads and executes malicious Perl scripts from a remote server. This can lead to unauthorized access, data loss, and system compromise.
Mitigation:
To mitigate this vulnerability, ensure that the topic.php file properly sanitizes user input and does not allow command injection. Additionally, keep all software and libraries up to date to prevent known vulnerabilities from being exploited.