vendor:
WebBBS
by:
nerF gr0up
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: WebBBS
Affected Version From: All versions up to 5.00
Affected Version To: All versions up to 5.00
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
WebBBS Remote Command Execution Vulnerability
WebBBS does not sufficiently filter shell metacharacters from CGI parameters. As a result, remote attackers may execute arbitrary commands on the underlying shell of the system hosting the vulnerable software. Remote attackers may gain local, interactive access to the host with the privileges of the webserver process as a result of successful exploitation.
Mitigation:
Filter user input to prevent malicious code injection.