Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1883 | exploit vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5438 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html | mailing list patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html | mailing list |
http://www.kootenayweb.bc.ca/scripts/whois.txt |