CVE-2002-1993
WebBBS 4 and 5.0 - Remote Command Execution via Followup Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1993. PoCs published by NERF Security.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in WebBBS (up to version 5.00) by injecting shell metacharacters into the 'followup' CGI parameter. It sends a crafted POST request to execute arbitrary commands on the underlying system with the privileges of the web server process.
Description
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.
Exploits (1)
This exploit leverages a command injection vulnerability in WebBBS (up to version 5.00) by injecting shell metacharacters into the 'followup' CGI parameter. It sends a crafted POST request to execute arbitrary commands on the underlying system with the privileges of the web server process.