CVE-2005-4694
Plain Black WebGUI < 6.7.6 - Remote Code Execution via Asset.pm www_add Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4694. PoCs published by David Maciejak.
AI-analyzed exploit summary This exploit leverages insufficient input sanitization in WebGUI to execute arbitrary commands via a crafted URL. The PoC demonstrates command injection by appending a semicolon and a command (`id`) to the `func` parameter.
Description
Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute arbitrary code via unknown attack vectors.
Exploits (1)
This exploit leverages insufficient input sanitization in WebGUI to execute arbitrary commands via a crafted URL. The PoC demonstrates command injection by appending a semicolon and a command (`id`) to the `func` parameter.