a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.
Affected Software
Name |
Vendor |
Start Version |
End Version |
A1stats |
Drummond_miles |
* |
1.6 |
References