Executive brief
AnyForm is a CGI script used to process web forms. A critical vulnerability allows remote attackers to execute arbitrary commands on the web server. This could lead to a complete system takeover, unauthorized access to sensitive data, or a total disruption of web services.
Technical details
AnyForm is vulnerable to a remote command execution flaw. The vulnerability exists in the CGI script's handling of input, allowing an unauthenticated remote attacker to inject and execute arbitrary shell commands via the network. This occurs because the script fails to properly sanitize user-supplied data before passing it to a system shell. Successful exploitation grants the attacker the privileges of the web server process, potentially leading to full host compromise.
Affected products
- AnyForm AnyForm
Timeline
- 1995-07-31: disclosed