Security Advisory
CVE-2008-6556
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the whois command.