Vulnerabilities > CVE-2005-0689 - Remote Command Execution vulnerability in The Includer 1.0/1.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description The Includer CGI. CVE-2005-0689. Webapps exploit for cgi platform id EDB-ID:922 last seen 2016-01-31 modified 2005-04-08 published 2005-04-08 reporter GreenwooD source https://www.exploit-db.com/download/922/ title The Includer CGI <= 1.0 - Remote Command Execution 1 description The Includer CGI. CVE-2005-0689. Webapps exploit for cgi platform id EDB-ID:923 last seen 2016-01-31 modified 2005-04-08 published 2005-04-08 reporter K-C0d3r source https://www.exploit-db.com/download/923/ title The Includer CGI <= 1.0 - Remote Command Execution 2 description The Includer CGI <= 1.0 Remote Command Execution. CVE-2005-0689. Webapps exploit for cgi platform id EDB-ID:862 last seen 2016-01-31 modified 2005-03-07 published 2005-03-07 reporter Francisco Alisson source https://www.exploit-db.com/download/862/ title The Includer CGI <= 1.0 - Remote Command Execution
Nessus
NASL family | CGI abuses |
NASL id | INCLUDER_RCMDEXEC.NASL |
description | The remote host is running The Includer, a PHP script for emulating server-side includes. The version of The Includer installed on the remote host allows an attacker to execute arbitrary shell commands by including shell metacharacters as part of the URL. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20296 |
published | 2005-12-12 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20296 |
title | The Includer includer.cgi Arbitrary Command Execution |
code |
|