Vulnerabilities (CVE)

Filtered by CWE-78
Total 3664 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0061 1 Apache 1 Http Server 2024-02-28 7.5 HIGH N/A
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
CVE-2002-1660 1 Jelsoft 1 Vbulletin 2024-02-28 7.5 HIGH N/A
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
CVE-2001-1583 1 Sun 1 Sunos 2024-02-28 10.0 HIGH N/A
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.
CVE-1999-0067 2 Apache, Ncsa 2 Http Server, Ncsa Httpd 2024-02-28 10.0 HIGH N/A
phf CGI program allows remote command execution through shell metacharacters.