Vulnerabilities > CVE-2005-2290
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
Summary
wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | WPS_SHOP_REMOTE_CMD_EXEC.NASL |
description | The remote host is running the WPS Web-Portal-System. The version of this software installed on the remote host is vulnerable to remote command execution flaw through the argument |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19306 |
published | 2005-07-27 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19306 |
title | WPS Web-Portal-System wps_shop.cgi art Parameter Arbitrary Command Injection |
code |
|
References
- http://marc.info/?l=bugtraq&m=112128870110418&w=2
- http://marc.info/?l=bugtraq&m=112128870110418&w=2
- http://secunia.com/advisories/15780
- http://secunia.com/advisories/15780
- http://securitytracker.com/id?1014480
- http://securitytracker.com/id?1014480
- http://www.securityfocus.com/bid/14245
- http://www.securityfocus.com/bid/14245