mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 00:28:04 +02:00
839 B
839 B
CVE-2020-24916
Description
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
POC
Reference
- https://github.com/vulnbe/poc-yaws-cgi-shell-injection
- https://packetstormsecurity.com/files/159106/Yaws-2.0.7-XML-Injection-Command-Injection.html
- https://vuln.be/post/yaws-xxe-and-shell-injections/