20100629 Miyabi CGI Tools index.pl command executionmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0614.html CVE-2010-2626
Miyabi CGI Tools 1.02 - 'index.pl' Remote Command Execution
Record summary
CVE-2010-2626 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMiyabi CGI Tools 1.02 - 'index.pl' Remote Command ExecutionExploitDB exploitby Marshall WhittakerNot analyzed1 file
References
720100629 Re: Miyabi CGI Tools index.pl command executionmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0615.html 65884vdb entry
http://osvdb.org/65884 40419Third-party advisory
http://secunia.com/advisories/40419 41228vdb entry
http://www.securityfocus.com/bid/41228 miyabi-index-command-execution(59908)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/59908 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-2626