[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-2765

Date: (C)2009-08-14   (M)2017-09-19
 
CVSS Score: 8.3Access Vector: ADJACENT_NETWORK
Exploitability Subscore: 6.5Access Complexity: LOW
Impact Subscore: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE











httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.

Reference:
SECTRACK-1022596
BID-35742
OSVDB-55990
EXPLOIT-DB-9209
http://isc.sans.org/diary.html?storyid=6853
http://metasploit.com/svn/framework3/trunk/modules/exploits/linux/http/ddwrt_cgibin_exec.rb
http://www.dd-wrt.com/
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=55173
http://www.theregister.co.uk/2009/07/21/critical_ddwrt_router_vuln/

CWE    1
CWE-20

© 2013 SecPod Technologies