Overview
Textor Webmasters Ltd listrec.pl CGI script does not properly validate input to the "TEMPLATE" CGI variable, allowing arbitrary command execution.
Description
The CGI script listrec.pl by Textor Webmasters Ltd does not properly validate input to the "TEMPLATE" CGI variable. This value is passed to a shell, allowing attackers to execute arbitrary commands with privileges of the web server process. |
Impact
Remote attackers can execute arbitrary commands with privileges of the web server. |
Solution
See Vendor Status section. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Alexey Sintsov for reporting this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
CVE IDs: | None |
Severity Metric: | 4.28 |
Date Public: | 2001-09-13 |
Date First Published: | 2002-09-24 |
Date Last Updated: | 2002-09-24 17:57 UTC |
Document Revision: | 5 |