CVE-2001-1343
WebStore 400/400CS 4.14 - Authenticated Remote Code Execution via ws_mail.cgi kill Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-1343. PoCs published by Igor Dobrovitski.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in cgiCentral's Webstore via the ws_mail.cgi script. It leverages improper input sanitization in the system() call to execute arbitrary Perl code, resulting in a reverse shell on port 23456.
Description
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.
Exploits (1)
This exploit targets a command injection vulnerability in cgiCentral's Webstore via the ws_mail.cgi script. It leverages improper input sanitization in the system() call to execute arbitrary Perl code, resulting in a reverse shell on port 23456.