Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-1888

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2004-1888
Last Modified 05 Sep 2008 04:42:37
Published 31 Dec 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-1888

Summary

display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.

Vulnerable Systems

Application

  • Aborior Encore Web Forum


References

XF - encore-display-command-execution(15725)

BID - 10040

BUGTRAQ - 20040403 Remote Exploit for Aborior's Encore Web Forum

SECTRACK - 1009652

BUGTRAQ - 20060621 Re: display.cgi

BUGTRAQ - 20060620 display.cgi

OSVDB - 16831


Last Updated: 27 May 2016 10:39:14