Описание
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.
Ссылки
- Patch
- Exploit
- PatchVendor Advisory
- Exploit
- Exploit
- Patch
- Exploit
- PatchVendor Advisory
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 24 (включая)
cpe:2.3:a:dd-wrt:dd-wrt:*:sp1:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.9168
Критический
8.3 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
почти 4 года назад
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.
EPSS
Процентиль: 100%
0.9168
Критический
8.3 High
CVSS2
Дефекты
CWE-20