Vulnerability Description
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Web-App.Org | Webapp | 0.9.9 |
Related Weaknesses (CWE)
References
- http://www.defacers.com.mx/advisories/3.txtURL Repurposed
- http://www.securityfocus.com/archive/1/449517/100/200/threaded
- http://www.securityfocus.com/archive/1/449573/100/200/threaded
- http://www.securityfocus.com/bid/13637Exploit
- http://www.soulblack.com.ar/repo/tools/sbwebapp.txt
- http://www.vupen.com/english/advisories/2005/0554Vendor Advisory
- http://www.defacers.com.mx/advisories/3.txtURL Repurposed
- http://www.securityfocus.com/archive/1/449517/100/200/threaded
- http://www.securityfocus.com/archive/1/449573/100/200/threaded
- http://www.securityfocus.com/bid/13637Exploit
- http://www.soulblack.com.ar/repo/tools/sbwebapp.txt
- http://www.vupen.com/english/advisories/2005/0554Vendor Advisory
FAQ
What is CVE-2005-1628?
CVE-2005-1628 is a vulnerability with a CVSS score of 7.5 (HIGH). apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
How severe is CVE-2005-1628?
CVE-2005-1628 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1628?
Check the references section above for vendor advisories and patch information. Affected products include: Web-App.Org Webapp.