PT-2002-2833 · Agh · Agh Htmlsearch
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2113
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
AGH HTMLsearch version 1.0
Description:
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the
template parameter of the search.cgi script.Recommendations:
For AGH HTMLsearch version 1.0, consider restricting access to the search.cgi script until a patch is available, and avoid using shell metacharacters in the
template parameter to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Agh Htmlsearch