Description
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Igor Dobrovitski · perlremotecgi
https://www.exploit-db.com/exploits/20916
Scores
EPSS
0.0590
EPSS Percentile
90.6%
Details
Status
published
Products (2)
cgicentral/webstore_400
4.14
cgicentral/webstore_400cs
4.14
Published
Jun 12, 2001
Tracked Since
Feb 18, 2026