CVE-2002-1993

WebBBS 4 and 5.0 - Remote Command Execution via Followup Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1993. PoCs published by NERF Security.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in WebBBS (up to version 5.00) by injecting shell metacharacters into the 'followup' CGI parameter. It sends a crafted POST request to execute arbitrary commands on the underlying system with the privileges of the web server process.

Description

webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NERF Security · perlwebappscgi
https://www.exploit-db.com/exploits/21567

This exploit leverages a command injection vulnerability in WebBBS (up to version 5.00) by injecting shell metacharacters into the 'followup' CGI parameter. It sends a crafted POST request to execute arbitrary commands on the underlying system with the privileges of the web server process.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WebBBS up to version 5.00
No auth needed
Prerequisites: Network access to the vulnerable WebBBS instance · Perl environment to run the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources mailing-list x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2002/06/msg00232.html
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9378.php
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5048

Scores

EPSS 0.1188
EPSS Percentile 95.6%

Details

Status published
Products (14)
affordable_web_space_design/affordable_web_space_design_webbbs 4.0
affordable_web_space_design/affordable_web_space_design_webbbs 4.1
affordable_web_space_design/affordable_web_space_design_webbbs 4.2
affordable_web_space_design/affordable_web_space_design_webbbs 4.10
affordable_web_space_design/affordable_web_space_design_webbbs 4.11
affordable_web_space_design/affordable_web_space_design_webbbs 4.12
affordable_web_space_design/affordable_web_space_design_webbbs 4.20
affordable_web_space_design/affordable_web_space_design_webbbs 4.21
affordable_web_space_design/affordable_web_space_design_webbbs 4.22
affordable_web_space_design/affordable_web_space_design_webbbs 4.30
... and 4 more
Published Dec 31, 2002
Tracked Since Feb 18, 2026