20050307 Remote Command Executionmailing list
http://marc.info/?l=bugtraq&m=111021730710779&w=2 CVE-2005-0689
The Includer CGI 1.0 - Remote Command Execution (1)
Record summary
CVE-2005-0689 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.
Description
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBThe Includer CGI 1.0 - Remote Command Execution (1)ExploitDB exploitby Francisco AlissonNot analyzed1 file
ExploitDBThe Includer CGI 1.0 - Remote Command Execution (2)ExploitDB exploitby GreenwooDNot analyzed1 file
ExploitDBThe Includer CGI 1.0 - Remote Command Execution (3)ExploitDB exploitby K-C0d3rNot analyzed1 file
References
420050308 Re: Remote Command Executionmailing list
http://marc.info/?l=bugtraq&m=111030957413411&w=2 12738vdb entry
http://www.securityfocus.com/bid/12738 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0689