Vulnerabilities > CVE-2003-0243 - Unspecified vulnerability in Happycgi Happymall 4.3/4.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description HappyMall E-Commerce Software 4.3/4.4 Normal_HTML.CGI Command Execution Vulnerability. CVE-2003-0243 . Webapps exploit for cgi platform id EDB-ID:22571 last seen 2016-02-02 modified 2003-05-07 published 2003-05-07 reporter Revin Aldi source https://www.exploit-db.com/download/22571/ title HappyMall E-Commerce Software 4.3/4.4 Normal_HTML.CGI Command Execution Vulnerability description HappyMall E-Commerce Software 4.3/4.4 Member_HTML.CGI Command Execution Vulnerability. CVE-2003-0243. Webapps exploit for cgi platform id EDB-ID:22572 last seen 2016-02-02 modified 2003-05-08 published 2003-05-08 reporter Revin Aldi source https://www.exploit-db.com/download/22572/ title HappyMall E-Commerce Software 4.3/4.4 Member_HTML.CGI Command Execution Vulnerability
Nessus
NASL family | CGI abuses |
NASL id | HAPPYMALL_CMD_EXEC.NASL |
description | There is a flaw HappyMall that could allow an attacker to execute arbitrary commands with the privileges of the HTTP daemon (typically root or nobody), by making a request like : /shop/normal_html.cgi?file=|id| In addition, member_html.cgi has been reported vulnerable. However, Nessus has not checked for this. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11602 |
published | 2003-05-08 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11602 |
title | HappyMall Multiple Script Arbitrary Command Execution |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/31114/unhappycgi.txt |
id | PACKETSTORM:31114 |
last seen | 2016-12-05 |
published | 2003-05-09 |
reporter | revin aldi |
source | https://packetstormsecurity.com/files/31114/unhappycgi.txt.html |
title | unhappycgi.txt |