header-logo
Suggest Exploit
vendor:
HTMLsearch Search Engine
by:
SecurityFocus
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: HTMLsearch Search Engine
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: ahg:htmlsearch
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Unix, Linux, and Microsoft
2002

Search.CGI Vulnerability

Search.CGI is a component of the HTMLsearch Search Engine software distributed by AHG. The software is available for the Unix, Linux, and Microsoft platforms. The search.cgi script included with the AHG Search Engine does not adequately filter input. Due to lack of sufficient input sanitization, it is possible for a remote user to pass semi-colon (;) and pipe (|) characters through a search request. This can result in the commands encapsulated between the symbols being executed with the privileges of the web server.

Mitigation:

Input validation should be used to ensure that user-supplied data is properly sanitized and filtered before being used in a command or query.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/3985/info

Search.CGI is a component of the HTMLsearch Search Engine software distributed by AHG. The software is available for the Unix, Linux, and Microsoft platforms.

The search.cgi script included with the AHG Search Engine does not adequately filter input. Due to lack of sufficient input sanitization, it is possible for a remote user to pass semi-colon (;) and pipe (|) characters through a search request. This can result in the commands encapsulated between the symbols being executed with the privileges of the web server.

http://www.example.com/cgi-bin/publisher/search.cgi?dir=jobs&template=;ls|&output_number=10