Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6176 (K+B-Bestellsystem)

BugsAlert Home > CVE-2007-6176 (K+B-Bestellsystem)
 
 

kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6176

Learn more about CVE-2007-6176 (K+B-Bestellsystem)
 
Tags: cve-2007-6176 b-bestellsystem

Related Items

      CVE-2007-6101 (Ability Mail Server)

      CVE-2008-0206 (Captcha)

      parameter elements force incorrect line breaks

      WF-Chat 1.0 Beta

      Bugtraq: rPSA-2008-0328-1 httpd mod_ssl

      Debian: New ekg packages fix denial of service

      pam_mount "passwdehd" Insecure Temporary Files

 

Pixel