CGI program executed an arbitrary command |
---|
Risk Level: | High | Check or Attack Name: cgiexec |
---|---|---|
Platforms: | Any | |
Description: | A vulnerable CGI program was detected. If a CGI program can be tricked into echoing characters, it can potentially be exploited to execute other commands that pose a security risk. |
|
Remedy: | Remove the offending cgi program, if possible. Otherwise, disable the program until the bug can be diagnosed and fixed. Make sure CGI programs do not pass unchecked user input to a shell for execution. |
|
References: |
Know Your Risks |