CVE-2010-2626

Miyabi CGI Tools SEO Links 1.02 - Remote Command Execution via fn Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-2626. PoCs published by Marshall Whittaker.

AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Miyabi CGI Tools 1.02 by injecting arbitrary commands via the 'fn' parameter in the URL. The PoC uses 'uname -a' to show command execution, but other commands could be injected similarly.

Description

index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Marshall Whittaker · textwebappscgi
https://www.exploit-db.com/exploits/34223

This exploit demonstrates a command injection vulnerability in Miyabi CGI Tools 1.02 by injecting arbitrary commands via the 'fn' parameter in the URL. The PoC uses 'uname -a' to show command execution, but other commands could be injected similarly.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Miyabi CGI Tools 1.02
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/65884
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/59908
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/41228
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40419
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0614.html

Scores

EPSS 0.1295
EPSS Percentile 95.8%

Details

CWE
CWE-94
Status published
Products (1)
miyabi-seo/cgi_tools_seo_links 1.02
Published Jul 02, 2010
Tracked Since Feb 18, 2026