Vulnerabilities > CVE-2004-1888 - Remote Arbitrary Command Execution vulnerability in Aborior Encore Web Forum
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Aborior Encore Web Forum Remote Arbitrary Command Execution Vulnerability. CVE-2004-1888. Webapps exploit for cgi platform |
id | EDB-ID:23907 |
last seen | 2016-02-02 |
modified | 2004-04-03 |
published | 2004-04-03 |
reporter | K-159 |
source | https://www.exploit-db.com/download/23907/ |
title | Aborior Encore Web Forum Remote Arbitrary Command Execution Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | ABORIOR_CMD_EXEC.NASL |
description | The remote host is running the Aborior Web Forum. There is a flaw in this version that could allow an attacker to execute arbitrary commands on this server with the privileges of the affected web server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12127 |
published | 2004-04-04 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12127 |
title | Aborior Encore WebForum display.cgi file Parameter Command Execution |
code |
|
References
- http://marc.info/?l=bugtraq&m=108100973820868&w=2
- http://www.osvdb.org/16831
- http://www.securityfocus.com/archive/1/437813/100/0/threaded
- http://www.securityfocus.com/archive/1/437978/100/0/threaded
- http://www.securityfocus.com/bid/10040
- http://www.securitytracker.com/id?1009652
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15725