Exploitation Summary
EIP tracks 1 public exploit for CVE-2001-1290. PoCs published by Igor Dobrovitski.
AI-analyzed exploit summary This exploit targets an origin validation error in Active Classifieds Free Edition, allowing unauthenticated administrative command execution. It overwrites a configuration file to inject Perl code that spawns a reverse shell on port 23456 when a specific cookie is supplied.
Description
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.
Exploits (1)
This exploit targets an origin validation error in Active Classifieds Free Edition, allowing unauthenticated administrative command execution. It overwrites a configuration file to inject Perl code that spawns a reverse shell on port 23456 when a specific cookie is supplied.