9.3
CVE-2007-3572
- EPSS 8.38%
- Veröffentlicht 05.07.2007 20:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:18
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.38% | 0.943 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0020.html
http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0092.html
http://osvdb.org/37808
http://secunia.com/advisories/25902
http://www.securityfocus.com/bid/24743
http://www.vupen.com/english/advisories/2007/2417
https://exchange.xforce.ibmcloud.com/vulnerabilities/35208