vendor:
mnoGoSearch
by:
pokleyzz
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: mnoGoSearch
Affected Version From: 3.1.20
Affected Version To: 3.1.20
Patch Exists: NO
Related CWE: Unknown
CPE: mnoGoSearch:3.1.20
Platforms Tested: Linux
Unknown
Remote Exploit for mnoGoSearch 3.1.20
This exploit allows remote command execution as the webserver user id in mnoGoSearch 3.1.20 for Linux ix86. The exploit takes advantage of a vulnerability in the search.cgi script.
Mitigation:
Upgrade to a patched version of mnoGoSearch.