go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter.
Link | Tags |
---|---|
https://github.com/mikaku/Monitorix/issues/30 | issue tracking exploit third party advisory |
http://openwall.com/lists/oss-security/2013/12/12/8 | third party advisory mailing list |
http://marc.info/?l=bugtraq&m=109164242705572&w=2 | third party advisory exploit |