CVE-2002-2113

AGH HTMLsearch 1.0 - Remote Command Execution via Template Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-2113. PoCs published by Aleksey Sintsov.

AI-analyzed exploit summary The exploit demonstrates a command injection vulnerability in AHG Search Engine's search.cgi script due to insufficient input sanitization. An attacker can execute arbitrary commands by injecting semi-colon or pipe characters in the 'template' parameter.

Description

search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aleksey Sintsov · textwebappscgi
https://www.exploit-db.com/exploits/21257

The exploit demonstrates a command injection vulnerability in AHG Search Engine's search.cgi script due to insufficient input sanitization. An attacker can execute arbitrary commands by injecting semi-colon or pipe characters in the 'template' parameter.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: AHG Search Engine (version not specified)
No auth needed
Prerequisites: Access to the vulnerable search.cgi endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3985
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8032.php

Scores

EPSS 0.0387
EPSS Percentile 88.9%

Details

Status published
Products (1)
agh/htmlsearch 1.0
Published Dec 31, 2002
Tracked Since Feb 18, 2026