20020618 WebBBS 5.0 (andlater versions) vulnerable: allow commands execution via "followup" bugmailing list
http://cert.uni-stuttgart.de/archive/bugtraq/2002/06/msg00232.html CVE-2002-1993
WebScripts WebBBS 4.x/5.0 - Remote Command Execution
Record summary
CVE-2002-1993 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWebScripts WebBBS 4.x/5.0 - Remote Command ExecutionExploitDB exploitby NERF SecurityNot analyzed1 file
References
4webbs-followup-execute-commands(9378)vdb entry
http://www.iss.net/security_center/static/9378.php 5048vdb entry
http://www.securityfocus.com/bid/5048 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1993