CVE-2005-1628
high · 7.5apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
7.5
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2005-05-17
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| web-app.org | webapp | 0.9.9 |
| web-app.org | webapp | 0.9.9.2 |
| web-app.org | webapp | 0.9.9.2.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.defacers.com.mx/advisories/3.txt
- http://www.securityfocus.com/archive/1/449517/100/200/threaded
- http://www.securityfocus.com/archive/1/449573/100/200/threaded
- http://www.securityfocus.com/bid/13637
- http://www.soulblack.com.ar/repo/tools/sbwebapp.txt
- http://www.vupen.com/english/advisories/2005/0554
- http://www.defacers.com.mx/advisories/3.txt
- http://www.securityfocus.com/archive/1/449517/100/200/threaded
- http://www.securityfocus.com/archive/1/449573/100/200/threaded
- http://www.securityfocus.com/bid/13637
- http://www.soulblack.com.ar/repo/tools/sbwebapp.txt
- http://www.vupen.com/english/advisories/2005/0554
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2005-1628