Vulnerabilities > CVE-2007-3572 - Unspecified vulnerability in Yoggie Pico and Pico PRO

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
yoggie
exploit available

Summary

Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).

Vulnerable Configurations

Part Description Count
Application
Yoggie
2

Exploit-Db

descriptionYoggie Pico and Pico Pro Backticks Remote Code Execution Vulnerability. CVE-2007-3572. Webapps exploit for cgi platform
idEDB-ID:30260
last seen2016-02-03
modified2007-07-02
published2007-07-02
reporterCody Brocious
sourcehttps://www.exploit-db.com/download/30260/
titleYoggie Pico and Pico Pro Backticks Remote Code Execution Vulnerability