VulnerabilityModified
CVE-2010-2626
index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command.
HIGH 7.5EPSS 12.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 12.95% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- miyabi-seo/cgi tools seo links
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0614.html
- http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0615.htmlExploit
- http://osvdb.org/65884
- http://secunia.com/advisories/40419Vendor Advisory
- http://www.securityfocus.com/bid/41228Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59908
- http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0614.html
- http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0615.htmlExploit
- http://osvdb.org/65884
- http://secunia.com/advisories/40419Vendor Advisory
- http://www.securityfocus.com/bid/41228Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59908
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.