CVE
- Id
- 2104
- CVE No.
- CVE-2000-0527
- Status
- Candidate
- Description
- userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
- Phase
- Proposed (20000712)
- Votes
- ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall
- Comments
- Christey> Modify description - explicitly mention %0a string; other | metachar"s are filtered | Frech> XF:mailstudio-cgi-input-vaildation(4739)