Description
A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to the 'ip' parameter allows attackers to execute arbitrary shell commands on the server via embedded base64-encoded payloads. Authentication may be required depending on deployment configuration.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 3.0 commit ac67be
Credits
bperry
References
raw.githubusercontent.com/...its/multi/http/gestioip_exec.rb
sourceforge.net/...ac67be9fce5ee4c0438d27dfa5c1dcbca08c457c/
sourceforge.net/projects/gestioip/
www.vulncheck.com/advisories/gestioip-rce