20010627 Active Web Classifieds failure to authenticate leads to arbitrary code executionmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-06/0386.html CVE-2001-1290
Active Classifieds 1.0 - Arbitrary Code Execution
Record summary
CVE-2001-1290 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBActive Classifieds 1.0 - Arbitrary Code ExecutionExploitDB exploitby Igor DobrovitskiNot analyzed1 file
References
512326vdb entry
http://www.osvdb.org/12326 2942vdb entry
http://www.securityfocus.com/bid/2942 active-classifieds-admin-access(6754)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6754 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1290