Vulnerabilities > CVE-2007-3572 - Remote Code Execution vulnerability in Yoggie Pico and Pico Pro Backticks

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
yoggie
critical
exploit available

Summary

Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences). The vendor has addressed this issue through the release of the following product update: http://www.yoggie.com/supportcase.asp

Vulnerable Configurations

Part Description Count
Application
Yoggie
2

Exploit-Db

descriptionYoggie Pico and Pico Pro Backticks Remote Code Execution Vulnerability. CVE-2007-3572. Webapps exploit for cgi platform
idEDB-ID:30260
last seen2016-02-03
modified2007-07-02
published2007-07-02
reporterCody Brocious
sourcehttps://www.exploit-db.com/download/30260/
titleYoggie Pico and Pico Pro Backticks Remote Code Execution Vulnerability