CVE Vulnerabilities

CVE-2007-3572

Published: Jul 05, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded ` (backtick) characters (%60 sequences).

Affected Software

Name Vendor Start Version End Version
Pico_pro Yoggie * *
Pico Yoggie * *

References