CVE-2001-1160
Microburst Technologies uDirectory <2.0 - Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-1160. PoCs published by Igor Dobrovitski.
AI-analyzed exploit summary This exploit targets an input validation error in uDirectory's ustore.pl CGI script, allowing remote command execution via crafted HTTP POST requests. It attempts to spawn a reverse shell on port 23456 by injecting Perl code through the 'category_file' parameter.
Description
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.
Exploits (1)
This exploit targets an input validation error in uDirectory's ustore.pl CGI script, allowing remote command execution via crafted HTTP POST requests. It attempts to spawn a reverse shell on port 23456 by injecting Perl code through the 'category_file' parameter.