20050609 Webhints v1.03 Remote Command Executionmailing list
http://marc.info/?l=bugtraq&m=111842893001406&w=2 CVE-2005-1950
Webhints 1.03 - Remote Command Execution (Perl) (1)
Record summary
CVE-2005-1950 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.
Description
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBWebhints 1.03 - Remote Command Execution (Perl) (1)ExploitDB exploitby Alpha_ProgrammerNot analyzed1 file
ExploitDBWebhints 1.03 - Remote Command Execution (C) (2)ExploitDB exploitby Alpha_ProgrammerNot analyzed1 file
ExploitDBWebhints 1.03 - Remote Command Execution (Perl) (3)ExploitDB exploitby MadSheepNot analyzed1 file
References
515652Third-party advisory
http://secunia.com/advisories/15652 1014173vdb entry
http://securitytracker.com/id?1014173 13930vdb entry
http://www.securityfocus.com/bid/13930 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1950